Google Associate Cloud EngineerConfiguring access and securityEasy

A company policy dictates that all users should only have the minimum necessary permissions to perform their job functions. You are tasked with granting a new developer the ability to view all resources within a Google Cloud project, but not modify them. Which IAM role should you assign directly to the developer's user account?

  1. AProject Editor
  2. BCloud Asset User
  3. COwner
  4. DViewer
Show answer & explanation

Correct answer: D. Viewer

The 'Viewer' role (roles/viewer) grants read-only access to all resources within a project, aligning perfectly with the requirement to view but not modify resources.

Why the other options are wrong

  • A. Project Editor grants broad read/write access, violating the principle of least privilege.
  • B. Cloud Asset User (roles/cloudasset.user) allows viewing Cloud Asset Inventory, but not necessarily all resources in the project in a general sense required here.
  • C. Owner grants full administrative access, including billing and IAM management, which is far too permissive.

Viewer IAM Role

A predefined IAM role in Google Cloud that grants read-only access to all resources within a project or organization.

  • Provides permissions like `compute.instances.get`, `storage.buckets.get`.
  • Does not grant permissions to modify, create, or delete resources.
  • Ideal for users who need to monitor or audit resources without making changes.

Memory trick: Owner rules all, Editor changes all, Viewer just sees all, Billing pays all.

More Configuring access and security questions