Professional Cloud Security EngineerConfiguring access within a cloud solution environmentHard
A security auditor is performing a compliance check and needs to verify that no user in a specific Google Cloud project has been granted the `roles/owner` or `roles/editor` roles directly. Instead, all users should only have custom roles or more granular predefined roles. Which `gcloud` command can be used to list all IAM policy bindings for a project to identify violations?
- A`gcloud projects get-iam-policy my-project --flatten="bindings[].members" --filter="bindings.role=(roles/owner OR roles/editor)"`
- B`gcloud logging read "resource.type=project AND protoPayload.methodName=SetIamPolicy" --project my-project`
- C`gcloud organizations get-iam-policy my-org --filter="bindings.role=(roles/owner OR roles/editor)"`
- D`gcloud iam roles list --project my-project --filter="name=(roles/owner OR roles/editor)"`
Show answer & explanationAnswer & explanation
Correct answer: A. `gcloud projects get-iam-policy my-project --flatten="bindings[].members" --filter="bindings.role=(roles/owner OR roles/editor)"`
The `gcloud projects get-iam-policy` command retrieves the IAM policy for a project. Using `--flatten="bindings[].members"` expands the policy bindings, and `--filter="bindings.role=(roles/owner OR roles/editor)"` specifically targets bindings where the role is 'owner' or 'editor', allowing the auditor to identify direct assignments of these broad roles.
Why the other options are wrong
- B. `gcloud logging read` queries audit logs for `SetIamPolicy` events, which is useful for *when* policies were changed, but not for viewing the *current state* of who holds which roles.
- C. This command retrieves the IAM policy for an *organization*, not a specific project, and wouldn't show direct project-level bindings unless they were inherited.
- D. `gcloud iam roles list` lists available IAM roles, not the members assigned to them within a project's policy.
gcloud IAM Policy Auditing
Using `gcloud` commands with `flatten` and `filter` to inspect and audit IAM policy bindings for specific roles or members within a Google Cloud project or organization.
- `get-iam-policy` retrieves the current policy.
- `--flatten` expands nested structures for easier filtering.
- `--filter` allows precise querying of results based on fields and values.
Memory trick: Get Policy, Filter Roles, Find Violations.