For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeGCP Associate Cloud Engineer (ACE)GCP Associate Cloud Engineer Practice Exam 1Question 44
    Hard1 markMultiple Choice
    Domain 5.1: Managing Identity and Access ManagementIAMCustom RolesDomain 5.1

    GCP ACE · Question 44 · Domain 5.1: Managing Identity and Access Management

    You are creating a custom IAM role because predefined roles provide too much access. Which TWO statements are true regarding custom IAM roles? (Select TWO)

    Answer options:

    A.

    Custom roles can only be created at the project or organization level, not the folder level.

    B.

    Custom roles automatically inherit new permissions when Google updates a service.

    C.

    You must manually maintain custom roles if Google adds new permissions to services.

    D.

    Custom roles can include permissions from any GCP service without restriction.

    E.

    Custom roles are recommended over predefined roles for all use cases.

    How to approach this question

    Understand the limitations and maintenance overhead of custom IAM roles.

    Full Answer

    Custom roles can only be created at the project or organization level, not the folder level. You must manually maintain custom roles if Google adds new permissions to services.
    Custom IAM roles allow you to combine specific permissions. However, they come with maintenance overhead: Google does not update them when new features/permissions are released. Also, custom roles can only be created at the Organization or Project level; they cannot be created at the Folder level.

    Common mistakes

    Assuming Google automatically updates custom roles like they do predefined roles.
    Question 43All questionsQuestion 45

    Practice the full GCP Associate Cloud Engineer Practice Exam 1

    50 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01What is the highest level of the Google Cloud resource hierarchy?EasyQ02You need to enable the Compute Engine API in a new project using the command line. Which command ...EasyQ03You are setting up a new GCP environment. You need to grant a group of developers access to view ...MediumQ04You want to receive an email notification when your GCP spending exceeds $1000 this month. What s...EasyQ05You need to analyze your GCP billing data using complex SQL queries to understand cost trends acr...Medium
    View all 50 questions →