Professional Cloud Security EngineerManaging operationsHard

A security auditor needs to verify that a Google Cloud organization's IAM policies adhere to the principle of least privilege across all projects. Specifically, they need to identify all users who have been granted the 'roles/editor' role directly on a project, rather than through a custom role with more granular permissions. Which Policy Intelligence tool is best suited for this task?

  1. APolicy Simulator
  2. BPolicy Analyzer
  3. CPolicy Troubleshooter
  4. DRecommender
Show answer & explanation

Correct answer: B. Policy Analyzer

Policy Analyzer is designed to analyze existing IAM policies to understand who has access to what resources and under what conditions. It can be used to audit broad roles like 'roles/editor' and identify where they are applied, helping to verify least privilege adherence.

Why the other options are wrong

  • A. Policy Simulator helps predict the effect of a policy change before it's applied, not for auditing existing roles.
  • C. Policy Troubleshooter helps understand why a principal has or doesn't have a specific permission, not for broad auditing of roles.
  • D. Recommender suggests improvements based on usage patterns but isn't a direct tool for auditing specific policy grants.

Policy Analyzer

A Google Cloud Policy Intelligence tool that helps security teams understand, audit, and verify existing IAM policies by analyzing who has access to what resources and under what conditions.

  • Audits existing IAM policies.
  • Identifies access paths and effective permissions.
  • Helps verify least privilege and compliance.
  • Can query policies across projects and organizations.

Memory trick: Policy Analyzer analyzes all policies, to see who's got what access.

More Managing operations questions