GCP ACE · Question 42 · Domain 5.1: Managing Identity and Access Management (IAM)
Your security team has requested that a specific automated script be granted permission to start and stop Compute Engine instances, but absolutely nothing else. You review the predefined IAM roles and find that none of them match this exact set of permissions without granting additional access.
What should you do?
Answer options:
Assign the roles/compute.instanceAdmin.v1 role.
Create a custom IAM role containing only the compute.instances.start and compute.instances.stop permissions.
Assign the primitive Editor role.
Modify an existing predefined role to remove the unwanted permissions.
50 questions · hints · full answers · grading