nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #343

Your organization leverages folders to represent different teams within your Google Cloud environment. To support Infrastructure as Code (IaC) practices, each team receives a dedicated service…

The correct answer is A. Grant each service account the folder administrator role on its respective folder. Granting each service account, the folder administrator role on its respective folder provides comprehensive permissions to manage all resources within that folder, including projects and resources, while limiting their scope to only their assigned folder. This approach follows…

Submitted by tarun92· Apr 18, 2026Configuring access within a cloud solution environment

Question

Your organization leverages folders to represent different teams within your Google Cloud environment. To support Infrastructure as Code (IaC) practices, each team receives a dedicated service account upon onboarding. You want to ensure that teams have comprehensive permissions to manage resources within their assigned folders while adhering to the principle of least privilege. You must design the permissions for these team-based service accounts in the most effective way possible. What should you do?

Options

  • AGrant each service account the folder administrator role on its respective folder.
  • BGrant each service account the project creator role at the organization level and use folder-level
  • CAssign each service account the project editor role at the organization level and instruct teams to
  • DAssign each service account the folder IAM administrator role on its respective folder to allow

How the community answered

(54 responses)
  • A
    72% (39)
  • B
    4% (2)
  • C
    9% (5)
  • D
    15% (8)

Explanation

Granting each service account, the folder administrator role on its respective folder provides comprehensive permissions to manage all resources within that folder, including projects and resources, while limiting their scope to only their assigned folder. This approach follows the principle of least privilege by restricting permissions to the folder level and avoids over-privileging at the organization level.

Topics

#IAM#Service Accounts#Least Privilege#Google Cloud Folders

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice