QuestionQ21

Managing security policies and access controls

Your organization’s IT department requires a dedicated auditor to oversee and validate activity in Google Vault. You must give the auditor complete read-only access to Vault retention policies and matters, while preventing the auditor from making changes or taking actions. What should you do?

  • A Assign the super admin role to the auditor and remove all privileges except “View All Matters.”
  • B Create a custom role with “View” privileges for Retention Policies and All Matters. Assign the role to the auditor.
  • C Create a custom role with the “View All Matters” privilege and assign the role to the auditor.
  • D Create a custom role with the “Manage Matters” privilege and assign the role to the auditor. Ensure the auditor is not assigned to any specific matters.
Explanation

The Google Vault privileges “View Retention Policies” and “View All Matters” provide read-only visibility into all organization-wide retention rules and all matters, respectively. Neither privilege grants the ability to create, modify, close, delete, or otherwise manage Vault resources.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!