GCP Professional Cloud Security Engineer Practice Question
Your company has deployed an internal administration portal on a group of Compute Engine instances behind an external HTTP(S) load balancer. Identity-Aware Proxy (IAP) has been enabled on the load balancer's backend service.
A group named [email protected] already has the following project-level IAM roles:
Compute Viewer (roles/compute.viewer)
Logging Viewer (roles/logging.viewer)
When members of the group browse to the portal, the IAP sign-in page appears, but after authentication they receive an HTTP 403 message saying they do not have access.
You must grant the minimum additional permission so that the group can reach the portal through IAP without allowing them to modify IAP or other resources.
Users need the predefined role IAP-Secured Web App User (roles/iap.httpsResourceAccessor) to establish a session through Identity-Aware Proxy and reach HTTPS resources protected by IAP. This role grants only the iap.webServiceVersions.access and related read-only permissions required for access; it does not allow enabling, disabling, or configuring IAP, nor does it provide broad project-wide privileges. The existing Compute Viewer and Logging Viewer roles supply visibility into resources and logs but grant no IAP access. IAP-Secured Tunnel User applies only to TCP forwarding tunnels, Project Editor violates least-privilege by giving write access to most services, and IAP Admin allows configuration changes to IAP itself. Therefore, assigning roles/iap.httpsResourceAccessor is the correct least-privilege solution.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Identity-Aware Proxy (IAP) in GCP?
Open an interactive chat with Bash
Why is IAP-Secured Web App User (roles/iap.httpsResourceAccessor) the right choice for accessing HTTPS resources protected by IAP?
Open an interactive chat with Bash
How does the principle of least privilege apply in GCP IAM roles?
Open an interactive chat with Bash
What is Identity-Aware Proxy (IAP) used for?
Open an interactive chat with Bash
What does the IAP-Secured Web App User role do?
Open an interactive chat with Bash
How does IAP-Secured Tunnel User differ from IAP-Secured Web App User?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .