QuestionQ57

Maintaining and automating data workloads

The company uses distinct Google Cloud projects for development, staging, and production. Developers require edit access to the development project, read-only access to the staging project, and no access to the production project. You need an effective, manageable way to assign and enforce these permissions in line with Google-recommended practices. What should you do?

Explanation

Google Cloud recommends using access groups to model job functions and granting IAM roles to groups rather than to individual users. Group membership centrally manages the developers’ permissions: assign the appropriate edit role in development and read-only role in staging to the relevant groups, while granting no IAM role in production. IAM roles control resource access; network firewalls, VPC Service Controls, and access levels do not replace these project-level IAM grants.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!