🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 27 minutes remaining!

GCP Professional Cloud Architect Practice Question

Your organization uses Shared VPC. The net-admins group must create and modify VPC networks, subnets, and firewall rules only in the host project. The app-ops group must create, start, stop, and delete Compute Engine VM instances in several service projects that use those subnets, but must not alter any network or firewall configuration. Using predefined IAM roles and least privilege, which approach meets these requirements?

  • Assign roles/compute.securityAdmin to the net-admins group on the host project, and assign roles/compute.networkUser to the app-ops group on each service project.

  • Assign roles/owner to the net-admins group on the host project, and roles/viewer to the app-ops group on each service project.

  • Assign roles/compute.instanceAdmin.v1 to the net-admins group on the host project, and roles/compute.networkAdmin to the app-ops group on each service project.

  • Assign roles/compute.networkAdmin to the net-admins group on the Shared VPC host project, and assign roles/compute.instanceAdmin.v1 to the app-ops group on each service project.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot