
Google CloudProfessional Cloud Security Engineer
Domain 1Objective 4
1.4 Managing and Implementing Authorization Controls PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice Questions (Page 5)
Part of the Configuring access domain, which accounts for 25% of the PROFESSIONAL-CLOUD-SECURITY-ENGINEER exam.
32questions here
7free pages
12concepts
25%of the exam
Questions 21–25
- 21
An organization wants to ensure that the person who creates a service account is not the same person who can grant that service account access to resources. Which principle does this practice enforce?
Select an answer first - 22
What is the primary difference between IAM and legacy Access Control Lists (ACLs) in Google Cloud?
Select an answer first - 23
Your organization has a folder-level policy that grants the Storage Admin role to a group of data scientists. A specific user in that group should not be able to delete any storage buckets, even though the group policy allows it. You need to explicitly prevent this user from deleting buckets while preserving all other group permissions. What should you do?
Select an answer first - 24
An organization wants to ensure that no user, including project owners, can delete a specific critical bucket. Which IAM feature should be used?
Select an answer first - 25
What is the primary use case for Privileged Access Manager (PAM)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.