Examtopics

Professional Cloud Security Engineer
  • Topic 1 Question 304

    You are managing a Google Cloud environment that is organized into folders that represent different teams. These teams need the flexibility to modify organization policies relevant to their work. You want to grant the teams the necessary permissions while upholding Google-recommended security practices and minimizing administrative complexity. What should you do?

    • Create a custom IAM role with the organization policy administrator permission and grant the permission to each team’s folder. Limit policy modifications based on folder names within the custom role’s definition.

    • Assign the organization policy administrator role to a central service account and provide teams with the credentials to use the service account when needed.

    • Create an organization-level tag. Attach the tag to relevant folders. Use an IAM condition to restrict the organization policy administrator role to resources with that tag.

    • Grant each team the organization policy administrator role at the organization level.


    シャッフルモード