🔥 40% Off Crucial Exams Memberships — Deal ends today!

44 minutes, 43 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization grants the Google Group "[email protected]" the Viewer role (roles/viewer) at the Organization node so that internal audit staff can list and read resources in every project. A new project called "mna-risk-analysis" will contain highly confidential data that auditors must not access. The project must stay within the existing organization hierarchy, and you must follow the principle of least privilege while avoiding disruptive changes to other projects. How should you prevent the auditors from viewing resources in the new project?

  • Attach an IAM Deny policy to the mna-risk-analysis project that blocks the [email protected] group from the viewer permissions they inherit.

  • Move the mna-risk-analysis project into a new Google Cloud organization that has no Viewer role for [email protected].

  • Delete the existing Viewer binding at the Organization level and re-create identical Viewer bindings on every other folder and project except mna-risk-analysis.

  • Add a conditional role binding at the project level that grants [email protected] the Viewer role only when resource.type != "project".

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot