nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #129

Your organization uses Cloud Identity as their identity provider (IdP) and is a Google Security Operations (SecOps) customer You need to grant a group of users access to the Google SecOps instance…

The correct answer is A. Create a Google Group and add the required users. Grant the roles/chronicle.Viewer IAM role to. To grant read-only access to all Google SecOps resources, including detection engine rules, you assign the roles/chronicle.Viewer IAM role. The correct method is to create a Google Group, add the required users, and grant this role to the group at the project level tied to your…

Security Operations Configuration and Administration

Question

Your organization uses Cloud Identity as their identity provider (IdP) and is a Google Security Operations (SecOps) customer You need to grant a group of users access to the Google SecOps instance with read-only access to all resources, including detection engine rules. How should this be configured?

Options

  • ACreate a Google Group and add the required users. Grant the roles/chronicle.Viewer IAM role to
  • BCreate a Google Group and add the required users. Grant the roles/chronicle.limitedViewer IAM
  • CCreate a workforce identity pool at the organization level. Grant the roles/chronicle.editor IAM role
  • DCreate a workforce identity pool at the organization level Grant the roles/chronicle.limitedViewer

How the community answered

(69 responses)
  • A
    77% (53)
  • B
    14% (10)
  • C
    6% (4)
  • D
    3% (2)

Explanation

To grant read-only access to all Google SecOps resources, including detection engine rules, you assign the roles/chronicle.Viewer IAM role. The correct method is to create a Google Group, add the required users, and grant this role to the group at the project level tied to your Google SecOps instance. This ensures consistent, least-privilege access management through Cloud Identity.

Topics

#IAM roles#chronicle.Viewer#Google Groups#Cloud Identity

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice