Hard1 markMultiple Choice

GCP ACE · Question 44 · Domain 5.1: Managing Identity and Access Management

You are creating a custom IAM role because predefined roles provide too much access. Which TWO statements are true regarding custom IAM roles? (Select TWO)

Answer options:

A.

Custom roles can only be created at the project or organization level, not the folder level.

B.

Custom roles automatically inherit new permissions when Google updates a service.

C.

You must manually maintain custom roles if Google adds new permissions to services.

D.

Custom roles can include permissions from any GCP service without restriction.

E.

Custom roles are recommended over predefined roles for all use cases.

How to approach this question

Understand the limitations and maintenance overhead of custom IAM roles.

Full Answer

Custom IAM roles allow you to combine specific permissions. However, they come with maintenance overhead: Google does not update them when new features/permissions are released. Also, custom roles can only be created at the Organization or Project level; they cannot be created at the Folder level.

Common mistakes

Assuming Google automatically updates custom roles like they do predefined roles.

Practice the full GCP Associate Cloud Engineer Practice Exam 1

50 questions · hints · full answers · grading

More questions from this exam