GCP Professional Cloud Architect Practice Question
Your organization uses Shared VPC. The net-admins group must create and modify VPC networks, subnets, and firewall rules only in the host project. The app-ops group must create, start, stop, and delete Compute Engine VM instances in several service projects that use those subnets, but must not alter any network or firewall configuration. Using predefined IAM roles and least privilege, which approach meets these requirements?
Assign roles/compute.instanceAdmin.v1 to the net-admins group on the host project, and roles/compute.networkAdmin to the app-ops group on each service project.
Assign roles/compute.networkAdmin to the net-admins group on the Shared VPC host project, and assign roles/compute.instanceAdmin.v1 to the app-ops group on each service project.
Assign roles/owner to the net-admins group on the host project, and roles/viewer to the app-ops group on each service project.
Assign roles/compute.securityAdmin to the net-admins group on the host project, and assign roles/compute.networkUser to the app-ops group on each service project.
Granting roles/compute.networkAdmin on the host project lets the net-admins group create and update VPC networks, subnets, and firewall rules while giving them no rights over VM instances. Granting roles/compute.instanceAdmin.v1 on each service project lets the app-ops group create and manage VM instances without permissions to change networks or firewall rules, maintaining separation of duties. The other options either grant excessive privileges or fail to provide required capabilities.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Shared VPC in GCP?
Open an interactive chat with Bash
What is the difference between roles/compute.networkAdmin and roles/compute.instanceAdmin.v1?
Open an interactive chat with Bash
Why is least privilege important in IAM role assignments?
Open an interactive chat with Bash
What is a Shared VPC in Google Cloud?
Open an interactive chat with Bash
What is the roles/compute.networkAdmin IAM role, and what does it allow?
Open an interactive chat with Bash
What is the roles/compute.instanceAdmin.v1 IAM role, and what does it allow?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .