Soru

Zorluk: KolayIdentity and Access Management (IAM) Roles and Resource Hierarchy

A security administration team needs to grant a group of compliance auditors read-only access to inspect resource configurations and review IAM policies across all projects grouped under a specific department folder in Google Cloud. Which TWO role assignments at the folder level satisfy these requirements while adhering to the principle of least privilege?

  1. Assign the Security Reviewer role (roles/iam.securityReviewer) to the auditor group at the folder level.Cevap
  2. Assign the Folder Viewer role (roles/resourcemanager.folderViewer) to the auditor group at the folder level.Cevap
  3. C
    Assign the primitive Owner role (roles/owner) to the auditor group at the folder level.
  4. D
    Assign the Service Account User role (roles/iam.serviceAccountUser) to the auditor group at the folder level.

Cevap

Assign the Security Reviewer role (roles/iam.securityReviewer) and the Folder Viewer role (roles/resourcemanager.folderViewer) to the auditor group at the folder level.
Granting the Security Reviewer role allows auditors to examine IAM bindings and security posture, while the Folder Viewer role enables them to view the resource hierarchy structure under the specified folder. Both roles follow the principle of least privilege by providing targeted read-only capabilities.

Adım Adım Çözüm

1
Identify the resource scope and inheritance level
The permissions must be applied at the folder level so that all underlying projects automatically inherit them.
Google Cloud IAM policy inheritance automatically applies parent folder permissions down to child projects.
2
Select least-privilege predefined security roles
Combining roles/iam.securityReviewer and roles/resourcemanager.folderViewer grants read access to security policies and resource structures.
Predefined roles provide narrow, purpose-specific capabilities required for auditing without enabling full resource modification.

Anahtar Kavram

IAM Policy Inheritance and Predefined Roles for Compliance Auditing
Tahmini Süre:1m 0s
Bu soruyu puanla