Google Associate Cloud EngineerConfiguring access and securityEasy
A company policy dictates that all users should only have the minimum necessary permissions to perform their job functions. You are tasked with granting a new developer the ability to view all resources within a Google Cloud project, but not modify them. Which IAM role should you assign directly to the developer's user account?
- AProject Editor
- BCloud Asset User
- COwner
- DViewer
Show answer & explanationAnswer & explanation
Correct answer: D. Viewer
The 'Viewer' role (roles/viewer) grants read-only access to all resources within a project, aligning perfectly with the requirement to view but not modify resources.
Why the other options are wrong
- A. Project Editor grants broad read/write access, violating the principle of least privilege.
- B. Cloud Asset User (roles/cloudasset.user) allows viewing Cloud Asset Inventory, but not necessarily all resources in the project in a general sense required here.
- C. Owner grants full administrative access, including billing and IAM management, which is far too permissive.
Viewer IAM Role
A predefined IAM role in Google Cloud that grants read-only access to all resources within a project or organization.
- Provides permissions like `compute.instances.get`, `storage.buckets.get`.
- Does not grant permissions to modify, create, or delete resources.
- Ideal for users who need to monitor or audit resources without making changes.
Memory trick: Owner rules all, Editor changes all, Viewer just sees all, Billing pays all.