Google Associate Cloud EngineerConfiguring access and securityMedium

A new project manager needs to manage virtual machine instances in a specific project, including starting, stopping, and deleting them. However, they should not have permissions to manage networks, disks, or other Compute Engine resources beyond the instances themselves. Which IAM role should be granted to the project manager?

  1. ACompute Admin
  2. BCompute Instance Admin (v1)
  3. CProject Editor
  4. DCompute Network Admin
Show answer & explanation

Correct answer: B. Compute Instance Admin (v1)

The Compute Instance Admin (v1) role provides comprehensive control over Compute Engine instances, allowing the project manager to start, stop, and delete VMs. This role adheres to the principle of least privilege by limiting access to instances and excluding other Compute Engine resources like networks and disks.

Why the other options are wrong

  • A. Compute Admin grants full control over all Compute Engine resources, which is too broad.
  • C. Project Editor grants broad editing permissions across the entire project, violating the principle of least privilege.
  • D. Compute Network Admin manages network resources, not Compute Engine instances directly.

Compute Instance Admin (v1) Role

The Compute Instance Admin (v1) role grants full control over Google Compute Engine virtual machine instances.

  • Allows starting, stopping, deleting, and modifying VM instances.
  • Does not grant permissions to manage networks, disks, or other Compute Engine infrastructure.
  • Ideal for users or service accounts focused solely on VM lifecycle management.

Memory trick: Instance Admin manages the VM, not the wires or storage.

More Configuring access and security questions