nerdexam
Google

ASSOCIATE-CLOUD-ENGINEER · Question #388

Your organization is migrating to Google Cloud. You want only users with company-issued Google accounts to access your Google Cloud environment. You must ensure that users of the same department can o

The correct answer is B. Assign users to the relevant Google Groups, and provide access to cloud resources through. This option meets the requirements by: Using Google Groups to manage department-specific user access. Applying IAM roles to control access to cloud resources based on departmental grouping. Leveraging organization policies to actively block non-company issued emails from accessin

Submitted by suresh_in· Mar 30, 2026Configuring access and security

Question

Your organization is migrating to Google Cloud. You want only users with company-issued Google accounts to access your Google Cloud environment. You must ensure that users of the same department can only access resources within their own department. You want to minimize operational costs while following Google-recommended practices. What should you do?

Options

  • AAssign users to the relevant Google Groups, and provide access to cloud resources through
  • BAssign users to the relevant Google Groups, and provide access to cloud resources through
  • CCreate a folder for each department in Resource Manager. Grant the users of each department the
  • DCreate a folder for each department in Resource Manager. Grant all company users the Folder

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    73% (16)
  • C
    5% (1)
  • D
    18% (4)

Explanation

This option meets the requirements by: Using Google Groups to manage department-specific user access. Applying IAM roles to control access to cloud resources based on departmental grouping. Leveraging organization policies to actively block non-company issued emails from accessing your Google Cloud environment. This approach is proactive, aligns with Google-recommended practices, and minimizes operational overhead by automating the enforcement of account restrictions.

Topics

#Google Groups#IAM role bindings#department-level access#identity management

Community Discussion

No community discussion yet for this question.

Full ASSOCIATE-CLOUD-ENGINEER Practice