Professional Cloud Security EngineerConfiguring access within a cloud solution environmentEasy

A security engineer is designing an access control strategy for a new Google Cloud project. The project will host multiple applications, each requiring distinct permissions to various Google Cloud services (e.g., Cloud Storage, Cloud SQL, Pub/Sub). The engineer wants to ensure that permissions are highly granular and tailored to the exact needs of each application, minimizing unnecessary privileges. Which IAM best practice should the engineer prioritize?

  1. AApply the Principle of Least Privilege by creating custom roles or using fine-grained predefined roles.
  2. BGrant project-level owner roles to all application service accounts for simplicity.
  3. CGrant broad organization-level roles to all service accounts to cover future needs.
  4. DUse predefined roles exclusively to avoid complexity.
Show answer & explanation

Correct answer: A. Apply the Principle of Least Privilege by creating custom roles or using fine-grained predefined roles.

The Principle of Least Privilege dictates that users and service accounts should only be granted the minimum necessary permissions to perform their tasks. This is achieved through fine-grained predefined roles or custom roles, which are essential for robust security.

Why the other options are wrong

  • B. Granting owner roles violates the principle of least privilege and creates significant security risks.
  • C. Granting broad organization-level roles is a major security vulnerability and directly contradicts the goal of minimizing unnecessary privileges.
  • D. While predefined roles are good, they might still be too broad for specific application needs, necessitating custom roles for true least privilege.

Principle of Least Privilege (PoLP)

The security principle that states users, programs, or processes should be granted only the minimum necessary permissions to perform their legitimate functions.

  • Reduces attack surface.
  • Limits impact of compromise.
  • Achieved with granular roles (custom or specific predefined).

Memory trick: Least privilege is the key to a secure cloud.

More Configuring access within a cloud solution environment questions