ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 14 - Professional Cloud Security Engineer discussion

Report
Export

A business unit at a multinational corporation signs up for GCP and starts moving workloads into GCP. The business unit creates a Cloud Identity domain with an organizational resource that has hundreds of projects.

Your team becomes aware of this and wants to take over managing permissions and auditing the domain resources.

Which type of access should your team grant to meet this requirement?

A.
Organization Administrator
Answers
A.
Organization Administrator
B.
Security Reviewer
Answers
B.
Security Reviewer
C.
Organization Role Administrator
Answers
C.
Organization Role Administrator
D.
Organization Policy Administrator
Answers
D.
Organization Policy Administrator
Suggested answer: C

Explanation:

Here are the permissions available to organizationRoleAdmin

iam.roles.create

iam.roles.delete

iam.roles.undelete

iam.roles.get

iam.roles.list

iam.roles.update

resourcemanager.projects.get

resourcemanager.projects.getIamPolicy

resourcemanager.projects.list

resourcemanager.organizations.get

resourcemanager.organizations.getIamPolicy

There are sufficient as per least privilege policy. You can do user management as well as auditing.

https://cloud.google.com/iam/docs/understanding-custom-roles

asked 18/09/2024
Stefan Denić
19 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first