Soru

Zorluk: KolayIdentity and Access Management (IAM) Roles and Resource Hierarchy

An organization wants to grant a central network administration team permissions to create and manage Virtual Private Cloud (VPC) networks across all Google Cloud projects within a specific department folder. Which IAM role assignment strategy follows Google Cloud best practices for resource hierarchy and least privilege?

  1. Grant the predefined Compute Network Admin role to the network administration group at the department folder level.Cevap
  2. B
    Grant the primitive Editor role to the network administration group at the department folder level.
  3. C
    Grant the Service Account Admin role to each individual member of the network administration group on every project.
  4. D
    Grant the Compute Network Admin role to each user account individually on every project within the department folder.

Cevap

Grant the predefined Compute Network Admin role to the network administration group at the department folder level.
Granting the predefined Compute Network Admin role at the folder level leverages resource hierarchy policy inheritance, automatically granting necessary network management permissions across all child projects while adhering strictly to the principle of least privilege.

Adım Adım Çözüm

1
Identify the required scope of permissions across the resource hierarchy.
Permissions must apply to all existing and future projects under the department folder.
IAM roles applied at a parent folder level are automatically inherited by all child resources.
2
Select the appropriate IAM role using least privilege guidelines.
The predefined Compute Network Admin role provides exact network management capabilities.
Predefined roles limit access specifically to required service resources without granting excessive control over unrelated services.

Anahtar Kavram

Resource Hierarchy IAM Role Inheritance and Least Privilege
Tahmini Süre:1m 0s
Bu soruyu puanla