GCP Professional Cloud Security Engineer Practice Question
Your organization operates over 120 Google Cloud projects contained in multiple folders. Today, each project's IAM policy grants roles directly to dozens of individual engineers. Because engineers frequently join, leave, or move between teams, project owners spend significant effort updating IAM policies and risk overlooking stale accounts. Security leadership asks for a solution that will sharply cut the number of IAM policy edits while still letting team leads quickly adjust who has access to their projects. Which strategy best meets these goals?
Replace individual role bindings with bindings that grant roles to Google Groups mapped to each engineering team, and delegate group membership management to team leads.
Enable IAM Recommender to automatically down-scope excessive permissions for each engineer across all projects.
Create custom IAM roles tailored to each engineer and bind them at the project level, updating the bindings when the engineer changes teams.
Use Access Context Manager to create an access level per engineer and add an IAM condition to every existing project-level binding.
Binding IAM roles to Google Groups that represent job functions or teams drastically reduces policy sprawl. Each project contains only a handful of bindings (roles ➜ groups). When an engineer joins or leaves a team, the team lead simply adds or removes the account from the appropriate group; the underlying IAM policies on all projects that reference the group automatically take effect without any additional edits. The other options either fail to reduce policy maintenance (custom roles per engineer), depend on conditional policies that still require per-binding updates (Access Context Manager), or provide recommendations rather than substituting for the fundamental need to streamline bindings (IAM Recommender).
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is IAM in Google Cloud?
Open an interactive chat with Bash
Why is using Google Groups for IAM roles better than assigning roles individually?
Open an interactive chat with Bash
How does IAM Recommender differ from using Google Groups for role management?
Open an interactive chat with Bash
What are Google Groups in the context of IAM policies?
Open an interactive chat with Bash
How does Access Context Manager differ from Google Groups in IAM management?
Open an interactive chat with Bash
What is IAM Recommender, and why is it not the best choice for this scenario?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .