Google Cloud Professional Cloud Architect · Free practice question 12 of 12
Cloud Asset Inventory IAM policy analysis
Before an audit, Harrowgate Bank's security team must find every principal that has roles granting BigQuery data access anywhere in the organization's 600 projects, including grants inherited from folders. What should the architect recommend?
- A.Cloud Asset Inventory IAM policy search and analysis across the organization
- B.Open the IAM page of each project in the console and record the grants
- C.Ask each project owner to submit a spreadsheet of who has access
- D.A query of Admin Activity audit logs for setIamPolicy calls made in the last 30 days across all projects
Show answer and explanation
Correct answer: A. Cloud Asset Inventory IAM policy search and analysis across the organization
Why: Cloud Asset Inventory can search IAM policies and analyze effective access across an organization, accounting for inheritance from folders and the organization. Checking 600 projects by hand is slow and misses inherited grants. Recent audit logs only show changes in that window, and owner-submitted spreadsheets are unreliable.
More free Google Cloud Professional Cloud Architect questions
- Config Sync GitOps across a cluster fleet
- Chirp speech model for call transcription
- AlloyDB read pools for read scaling
- VM Manager OS patch management
- BigQuery long-term storage pricing
- Feature Store against training-serving skew
- Autoclass for unpredictable object access
- Workflows orchestrating serverless steps
- Managed Service for Apache Airflow for complex DAGs
- Cloud DNS failover routing policy
- Datastream change data capture into BigQuery