
Google CloudProfessional Cloud Security Engineer
Domain 1Objective 4
1.4 Managing and Implementing Authorization Controls PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice Questions (Page 6)
Part of the Configuring access domain, which accounts for 25% of the PROFESSIONAL-CLOUD-SECURITY-ENGINEER exam.
32questions here
7free pages
12concepts
25%of the exam
Questions 26–30
- 26
What is the purpose of an IAM condition in a role binding?
Select an answer first - 27
A contractor needs temporary access to a Compute Engine instance in your project to perform a one-time migration. The access should be limited to the next 48 hours and only from the contractor's corporate IP address. You need to grant this access using IAM. What should you do?
Select an answer first - 28
What is the primary purpose of an IAM deny policy?
Select an answer first - 29
Your security team has identified that a user has the Owner role on a project, but the user only needs to manage Cloud Storage resources. You need to determine the minimal set of permissions the user actually uses and recommend a least-privilege role. You also need to ensure that the recommendation is based on actual usage data. What should you do?
Select an answer first - 30
A user reports they cannot access a resource. Which Policy Intelligence tool should be used to determine why the access is failing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.