🔥 40% Off Crucial Exams Memberships — Deal ends today!

3 hours, 1 minute remaining!

GCP Professional Cloud Security Engineer Practice Question

A security team wants to tighten access controls in a large GCP organization where IAM roles are currently bound to dozens of individual user principals. Their goals are to 1) simplify future permission reviews, 2) delegate day-to-day onboarding and off-boarding of developers to team leads, and 3) ensure that no users accidentally retain permissions after leaving a group. Which approach best meets ALL three goals?

  • Assign broad organization-wide roles (such as roles/viewer) directly to every user and rely on audit logs to detect misuse.

  • Create least-privilege Google Groups for each functional role, grant all required IAM roles to those groups, and delegate group-membership administration to team leads while synchronizing group membership with the corporate directory.

  • Require every project owner to manage IAM bindings for their own project resources instead of centralizing permissions in groups.

  • Keep existing individual IAM bindings but place all projects inside a VPC Service Control perimeter to prevent lateral movement and data exfiltration.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot