GCP Professional Cloud Security Engineer Practice Question
During a PCI compliance audit, your organization must prove that only authorized identities can start Compute Engine instances. You are asked to deliver, within hours, a single report that enumerates every principal who currently has the compute.instances.start permission in any project under the Payments folder, taking into account all inherited IAM bindings and custom roles. You cannot modify policies and want to avoid writing custom scripts. Which Policy Intelligence capability should you use to satisfy this requirement?
Run an access analysis on the Payments folder with Policy Analyzer and export the results.
Use IAM Recommender to generate least-privilege role suggestions for the Payments folder.
Review Access Approval logs to identify identities that requested Compute Engine start approvals.
Execute Policy Troubleshooter for each principal and aggregate the outcomes manually.
The IAM Policy Analyzer is designed to answer the question "who has what access to which resources?" It can analyze effective IAM policies over an entire scope-project, folder, or organization-evaluate inherited and custom role bindings, and export a comprehensive report of all principals granted a specific permission such as compute.instances.start. IAM Recommender focuses on right-sizing over-permissive bindings rather than listing current access. Policy Troubleshooter helps diagnose access for a single principal-resource pair, not bulk reporting. Access Approval logs only record user approval requests and do not enumerate all principals with a permission. Therefore, Policy Analyzer is the appropriate tool.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the IAM Policy Analyzer?
Open an interactive chat with Bash
How does inheritance work in IAM roles?
Open an interactive chat with Bash
What is the difference between IAM Policy Analyzer and IAM Recommender?
Open an interactive chat with Bash
What is IAM Policy Analyzer?
Open an interactive chat with Bash
How does Policy Analyzer evaluate inherited IAM bindings?
Open an interactive chat with Bash
What is the difference between Policy Analyzer and Policy Troubleshooter?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .