nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #55

A business unit at a multinational corporation signs up for GCP and starts moving workloads into GCP. The business unit creates a Cloud Identity domain with an organizational resource that has…

The correct answer is A. Organization Administrator. The Organization Administrator role (A) grants the broadest level of control over a GCP organization. It allows managing all IAM policies at every level (org, folder, project), viewing and auditing all resources, and configuring organizational settings - exactly what is needed…

Submitted by marco_it· Apr 18, 2026Configuring access within a cloud solution environment

Question

A business unit at a multinational corporation signs up for GCP and starts moving workloads into GCP. The business unit creates a Cloud Identity domain with an organizational resource that has hundreds of projects. Your team becomes aware of this and wants to take over managing permissions and auditing the domain resources. Which type of access should your team grant to meet this requirement?

Options

  • AOrganization Administrator
  • BSecurity Reviewer
  • COrganization Role Administrator
  • DOrganization Policy Administrator

How the community answered

(59 responses)
  • A
    81% (48)
  • B
    10% (6)
  • C
    3% (2)
  • D
    5% (3)

Explanation

The Organization Administrator role (A) grants the broadest level of control over a GCP organization. It allows managing all IAM policies at every level (org, folder, project), viewing and auditing all resources, and configuring organizational settings - exactly what is needed to take over governance of an organization. Security Reviewer (B) is a read-only role limited to viewing security configuration and audit logs; it cannot manage permissions. Organization Role Administrator (C) only manages the lifecycle of custom IAM roles, not broader permission management. Organization Policy Administrator (D) manages org-level constraint policies (e.g., disabling service account key creation) but cannot manage IAM bindings or audit resource access across projects.

Topics

#IAM Roles#Organization Management#Access Control#Cloud Identity

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice