Medium1 markMultiple Choice

GCP ACE · Question 03 · Domain 1.1: Setting up cloud projects and accounts

You are setting up a new GCP environment. You need to grant a group of developers access to view resources in a specific project, but they should not be able to modify anything. Which TWO actions should you take? (Select TWO)

Answer options:

A.

Create a Google Group and add the developers to it.

B.

Assign the roles/viewer role to each developer's individual user account.

C.

Assign the roles/editor role to the Google Group at the project level.

D.

Assign the roles/viewer role to the Google Group at the project level.

E.

Create a Service Account for the developers to share.

How to approach this question

Identify the best practice for grouping users (Google Groups) and the appropriate least-privilege role (Viewer).

Full Answer

Google Cloud best practices dictate using Google Groups to manage access for teams. This makes onboarding and offboarding easier. The `roles/viewer` primitive role grants read-only access to almost all resources in the project, satisfying the requirement that they cannot modify anything.

Common mistakes

Selecting individual user assignment instead of group assignment, or selecting a role with too many permissions.

Practice the full GCP Associate Cloud Engineer Practice Exam 1

50 questions · hints · full answers · grading

More questions from this exam