Google Cloud Digital LeaderSecurity and operations with Google CloudMedium

A global consulting firm uses Google Cloud for client projects, often involving highly sensitive data. They need to adhere to the principle of least privilege, ensuring that users and service accounts only have the minimum necessary permissions to perform their tasks across all Google Cloud resources. Which Google Cloud security concept is fundamental to implementing this principle?

  1. AResource Hierarchy
  2. BSecurity Command Center
  3. CIdentity and Access Management (IAM)
  4. DOrganization Policy Service
Show answer & explanation

Correct answer: C. Identity and Access Management (IAM)

Identity and Access Management (IAM) is Google Cloud's fundamental service for managing who (identities) can do what (roles) on which resources, directly enabling the implementation of the principle of least privilege.

Why the other options are wrong

  • A. Resource Hierarchy organizes resources, but doesn't directly manage permissions.
  • B. Security Command Center provides security insights and risk management, not direct permission management.
  • D. Organization Policy Service defines constraints across an organization, not individual user/service account permissions.

Identity and Access Management (IAM)

IAM is Google Cloud's authorization system that allows you to manage who can take action on specific Google Cloud resources.

  • Comprises members (who), roles (what they can do), and resources (where).
  • Enables fine-grained access control down to individual resources.
  • Fundamental for implementing the principle of least privilege.

Memory trick: IAM Manages Principles of Least Privilege.

More Security and operations with Google Cloud questions