PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #129
Your organization uses Cloud Identity as their identity provider (IdP) and is a Google Security Operations (SecOps) customer You need to grant a group of users access to the Google SecOps instance…
The correct answer is A. Create a Google Group and add the required users. Grant the roles/chronicle.Viewer IAM role to. To grant read-only access to all Google SecOps resources, including detection engine rules, you assign the roles/chronicle.Viewer IAM role. The correct method is to create a Google Group, add the required users, and grant this role to the group at the project level tied to your…
Question
Your organization uses Cloud Identity as their identity provider (IdP) and is a Google Security Operations (SecOps) customer You need to grant a group of users access to the Google SecOps instance with read-only access to all resources, including detection engine rules. How should this be configured?
Options
- ACreate a Google Group and add the required users. Grant the roles/chronicle.Viewer IAM role to
- BCreate a Google Group and add the required users. Grant the roles/chronicle.limitedViewer IAM
- CCreate a workforce identity pool at the organization level. Grant the roles/chronicle.editor IAM role
- DCreate a workforce identity pool at the organization level Grant the roles/chronicle.limitedViewer
How the community answered
(69 responses)- A77% (53)
- B14% (10)
- C6% (4)
- D3% (2)
Explanation
To grant read-only access to all Google SecOps resources, including detection engine rules, you assign the roles/chronicle.Viewer IAM role. The correct method is to create a Google Group, add the required users, and grant this role to the group at the project level tied to your Google SecOps instance. This ensures consistent, least-privilege access management through Cloud Identity.
Topics
Community Discussion
No community discussion yet for this question.