GCP ACE · Question 43 · Domain 5.1: Managing Identity and Access Management (IAM)
A user is granted the 'Compute Viewer' role at the Folder level. However, at the Project level (which is inside that Folder), the user is explicitly granted the 'Compute Admin' role.
What level of access does the user have to Compute Engine resources in that project?
Answer options:
The user has 'Compute Viewer' access because higher-level policies override lower-level policies.
The user has 'Compute Admin' access because IAM policies are a union of all granted roles.
The user has no access because the conflicting policies cancel each other out.
The user has 'Compute Viewer' access because the least privilege principle is automatically enforced by IAM.
50 questions · hints · full answers · grading