nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #12

Your team wants to limit users with administrative privileges at the organization level. Which two roles should your team restrict? (Choose two.)

The correct answer is A. Organization Administrator B. Super Admin. Organization Administrator and Super Admin are the two roles that grant the highest level of administrative privileges at the Google Cloud organization level. Organization Administrator can manage IAM policies, folders, and organization-wide settings. Super Admin (a Google…

Submitted by brentm· Apr 18, 2026Configuring access within a cloud solution environment

Question

Your team wants to limit users with administrative privileges at the organization level. Which two roles should your team restrict? (Choose two.)

Options

  • AOrganization Administrator
  • BSuper Admin
  • CGKE Cluster Admin
  • DCompute Admin
  • EOrganization Role Viewer

How the community answered

(26 responses)
  • A
    92% (24)
  • C
    4% (1)
  • E
    4% (1)

Explanation

Organization Administrator and Super Admin are the two roles that grant the highest level of administrative privileges at the Google Cloud organization level. Organization Administrator can manage IAM policies, folders, and organization-wide settings. Super Admin (a Google Workspace/Cloud Identity role) can manage all users, groups, and organizational settings, including recovering the organization. Both represent the broadest blast radius if compromised. GKE Cluster Admin (C) and Compute Admin (D) are project-scoped resource roles with no organization-level authority. Organization Role Viewer (E) is a read-only role and poses minimal risk.

Topics

#Google Cloud IAM#Organization Level Roles#Administrative Privileges#Role-Based Access Control

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice