PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #74
Your company uses Cloud Identity to manage employee identities and has Google Security Operations (SecOps) linked to your Google Cloud project. You have assigned the roles/chronicle.viewer IAM role…
The correct answer is C. The constraints/iam.allowedPolicyMemberDomains organization policy is restricting IAM role. The most likely cause is the constraints/iam.allowedPolicyMemberDomains organization policy. This policy can restrict IAM role assignments to identities within specific domains, preventing external users from accessing Google SecOps even if they are in a Google Group granted…
Question
Your company uses Cloud Identity to manage employee identities and has Google Security Operations (SecOps) linked to your Google Cloud project. You have assigned the roles/chronicle.viewer IAM role at the project level to a specific Google Group that contains users with external Google accounts. Users in this external group authenticate successfully to Google Cloud, but are unable to access Google SecOps. Internal users granted the same role can access Google SecOps. What Google Cloud configuration is most likely preventing the external users from accessing Google SecOps?
Options
- AExternal users must be synchronized to Cloud Identity using Google Cloud Directory Sync
- BGoogle SecOps inherently blocks sign-ins from identities outside the organization's primary
- CThe constraints/iam.allowedPolicyMemberDomains organization policy is restricting IAM role
- DThe roles/chronicle.viewer IAM role does not apply correctly when granted to Google Groups
How the community answered
(32 responses)- A9% (3)
- B3% (1)
- C84% (27)
- D3% (1)
Explanation
The most likely cause is the constraints/iam.allowedPolicyMemberDomains organization policy. This policy can restrict IAM role assignments to identities within specific domains, preventing external users from accessing Google SecOps even if they are in a Google Group granted the role. Internal users are unaffected because their identities match the allowed domain.
Topics
Community Discussion
No community discussion yet for this question.