nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #215

You are auditing all your Google Cloud resources in the production project. You want to identify all principals who can change firewall rules. What should you do?

The correct answer is D. Use Policy Analyzer to query the permissions compute.firewalls.create or. To identify all principals who can change firewall rules, you should use Policy Analyzer to query for the permissions related to creating, updating, or deleting firewall rules. These permissions are usually associated with compute.firewalls.create, compute.firewalls.update, and…

Submitted by obi.ng· Apr 18, 2026Configuring access within a cloud solution environment

Question

You are auditing all your Google Cloud resources in the production project. You want to identify all principals who can change firewall rules. What should you do?

Options

  • AUse Policy Analyzer to query the permissions compute.firewalls.get or compute.firewalls.list.
  • BUse Firewall Insights to understand your firewall rules usage patterns.
  • CReference the Security Health Analytics - Firewall Vulnerability Findings in the Security Command
  • DUse Policy Analyzer to query the permissions compute.firewalls.create or

How the community answered

(43 responses)
  • A
    5% (2)
  • B
    9% (4)
  • C
    5% (2)
  • D
    81% (35)

Explanation

To identify all principals who can change firewall rules, you should use Policy Analyzer to query for the permissions related to creating, updating, or deleting firewall rules. These permissions are usually associated with compute.firewalls.create, compute.firewalls.update, and compute.firewalls.delete. By checking which principals have these permissions, you can determine who has the ability to change firewall rules in your Google Cloud project.

Topics

#IAM#Firewall rules#Security auditing#Policy Analyzer

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice