nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #324

You are managing a Google Cloud environment that is organized into folders that represent different teams. These teams need the flexibility to modify organization policies relevant to their work…

The correct answer is C. Create an organization-level tag. Attach the tag to relevant folders. Use an IAM condition to. Granular Control: Creating an organization-level tag allows you to precisely control which teams have access to modify organization policies by attaching the tag to relevant folders. This ensures that only authorized teams can make changes. IAM Condition: Using an IAM condition…

Submitted by eva_at· Apr 18, 2026Configuring access within a cloud solution environment

Question

You are managing a Google Cloud environment that is organized into folders that represent different teams. These teams need the flexibility to modify organization policies relevant to their work. You want to grant the teams the necessary permissions while upholding Google- recommended security practices and minimizing administrative complexity. What should you do?

Options

  • ACreate a custom IAM role with the organization policy administrator permission and grant the
  • BAssign the organization policy administrator role to a central service account and provide teams
  • CCreate an organization-level tag. Attach the tag to relevant folders. Use an IAM condition to
  • DGrant each team the organization policy administrator role at the organization level.

How the community answered

(51 responses)
  • A
    6% (3)
  • B
    10% (5)
  • C
    82% (42)
  • D
    2% (1)

Explanation

Granular Control: Creating an organization-level tag allows you to precisely control which teams have access to modify organization policies by attaching the tag to relevant folders. This ensures that only authorized teams can make changes. IAM Condition: Using an IAM condition to restrict the organization policy administrator role to resources with the tag provides a flexible and efficient way to grant permissions while maintaining control. This ensures that the role is only accessible for the intended teams. Security Best Practices: This approach aligns with Google-recommended security practices by limiting access to organization policies to authorized teams and using IAM conditions to enforce appropriate controls. Administrative Efficiency: This approach simplifies administration by providing a centralized mechanism for managing permissions and ensuring that only authorized teams can modify organization policies.

Topics

#IAM#Organization Policies#Tags#Conditional Access

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice