Soru

Zorluk: KolayConfiguring Cloud Logging, Monitoring, and Operational Alerting

An infrastructure administrator needs to allow the operations team to create and manage Cloud Monitoring alerting policies within a Google Cloud project. Following the principle of least privilege, which IAM role should be granted to the operations team?

  1. Monitoring Editor (roles/monitoring.editor)Cevap
  2. B
    Owner (roles/owner)
  3. C
    Service Account User (roles/iam.serviceAccountUser)
  4. D
    Request a regional compute quota increase prior to creating the notification channels

Cevap

Granting the Monitoring Editor (roles/monitoring.editor) role is the correct approach because it provides the necessary permissions to manage operational alerts while following least-privilege principles.
The Monitoring Editor role (roles/monitoring.editor) grants full access to Cloud Monitoring configuration, including creating, updating, and deleting alerting policies and notification channels, while remaining strictly limited to monitoring capabilities in accordance with least-privilege practices.

Adım Adım Çözüm

1
Identify the required operational capability
The operations team requires access to configure and manage Cloud Monitoring alerting policies.
Alerting policy management is part of the operational monitoring domain in Google Cloud.
2
Evaluate IAM roles according to least privilege
The predefined Monitoring Editor role provides complete access to Monitoring resources (dashboards, alert policies, uptime checks) without granting administrative access to other service components or broad project permissions.
Predefined role assignment avoids over-granting privileges like primitive roles or non-relevant IAM permissions.

Anahtar Kavram

Configuring least-privilege IAM access for Cloud Monitoring and operational alerting
Bu soruyu puanla