CertKeen

Google Cloud Professional Cloud Architect · Free practice question 12 of 12

Cloud Asset Inventory IAM policy analysis

Before an audit, Harrowgate Bank's security team must find every principal that has roles granting BigQuery data access anywhere in the organization's 600 projects, including grants inherited from folders. What should the architect recommend?

  1. A.Cloud Asset Inventory IAM policy search and analysis across the organization
  2. B.Open the IAM page of each project in the console and record the grants
  3. C.Ask each project owner to submit a spreadsheet of who has access
  4. D.A query of Admin Activity audit logs for setIamPolicy calls made in the last 30 days across all projects
Show answer and explanation

Correct answer: A. Cloud Asset Inventory IAM policy search and analysis across the organization

Why: Cloud Asset Inventory can search IAM policies and analyze effective access across an organization, accounting for inheritance from folders and the organization. Checking 600 projects by hand is slow and misses inherited grants. Recent audit logs only show changes in that window, and owner-submitted spreadsheets are unreliable.

More free Google Cloud Professional Cloud Architect questions