PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #55
A business unit at a multinational corporation signs up for GCP and starts moving workloads into GCP. The business unit creates a Cloud Identity domain with an organizational resource that has…
The correct answer is A. Organization Administrator. The Organization Administrator role (A) grants the broadest level of control over a GCP organization. It allows managing all IAM policies at every level (org, folder, project), viewing and auditing all resources, and configuring organizational settings - exactly what is needed…
Question
Options
- AOrganization Administrator
- BSecurity Reviewer
- COrganization Role Administrator
- DOrganization Policy Administrator
How the community answered
(59 responses)- A81% (48)
- B10% (6)
- C3% (2)
- D5% (3)
Explanation
The Organization Administrator role (A) grants the broadest level of control over a GCP organization. It allows managing all IAM policies at every level (org, folder, project), viewing and auditing all resources, and configuring organizational settings - exactly what is needed to take over governance of an organization. Security Reviewer (B) is a read-only role limited to viewing security configuration and audit logs; it cannot manage permissions. Organization Role Administrator (C) only manages the lifecycle of custom IAM roles, not broader permission management. Organization Policy Administrator (D) manages org-level constraint policies (e.g., disabling service account key creation) but cannot manage IAM bindings or audit resource access across projects.
Topics
Community Discussion
No community discussion yet for this question.