
Answer-first summary for fast verification
Answer: Assign the Monitoring Editor role to the team in the Project where the monitoring workspace will be created.
The principle of least privilege is a critical security practice that advocates for granting users or teams only the access they need to perform their duties, nothing more. In this context, the team's responsibility is to create monitoring workspaces. The Monitoring Editor role is ideal as it permits the creation, modification, and deletion of monitoring configurations, alerts, and dashboards, without extending unnecessary access to other project resources. This role aligns perfectly with the principle of least privilege, enabling the team to accomplish their tasks efficiently without overstepping their required permissions. Granting the Project Editor or Project Owner roles would provide excessive access to project resources, contravening the principle of least privilege. Similarly, the Monitoring Admin role offers more privileges than necessary for workspace creation. For further details, consult the Google Cloud documentation on Monitoring access control and Understanding roles.
Author: LeetQuiz Editorial Team
Ultimate access to all questions.
Your company manages multiple Google Cloud projects within its organization. As part of enhancing the monitoring strategy, these projects are to be integrated into designated workspaces. Your team is responsible for setting up these workspaces. Adhering to the principle of least privilege, which IAM role should be assigned to your team to facilitate the creation of workspaces?
A
Assign the Monitoring Editor role to the team in the Project where the monitoring workspace will be created.
B
Assign the Project Owner role to the team in the Project where the monitoring workspace will be created.
C
Assign the Project Editor role to the team in the Project where the monitoring workspace will be created.
D
Assign the Monitoring Admin role to the team in the Project where the monitoring workspace will be created.
No comments yet.