GCP ACE · Question 43 · Domain 5.1: Managing Identity and Access Management (IAM)
You are reviewing the IAM policies in your organization and realize that a predefined role grants slightly more permissions than your security team allows. You decide to create a Custom IAM role.
Which TWO statements are true regarding Custom IAM roles? (Select TWO)
You are reviewing the IAM policies in your organization and realize that a predefined role grants slightly more permissions than your security team allows. You decide to create a Custom IAM role.
Which TWO statements are true regarding Custom IAM roles? (Select TWO)
Answer options:
Custom roles can be created at the Folder level.
Custom roles can be created at the Project or Organization level.
Google automatically updates your Custom roles with new permissions when new GCP services are released.
You are responsible for maintaining Custom roles and updating them if new permissions are required for a service.
Custom roles can include permissions that are not supported by any predefined roles.
How to approach this question
Full Answer
Common mistakes
Practice the full GCP Associate Cloud Engineer Practice Exam 6
50 questions · hints · full answers · grading
Expert