Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 29 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 29
Topic #: 1
[All Professional Cloud Security Engineer Questions]

Your team sets up a Shared VPC Network where project co-vpc-prod is the host project. Your team has configured the firewall rules, subnets, and VPN gateway on the host project. They need to enable Engineering Group A to attach a Compute Engine instance to only the 10.1.1.0/24 subnet.
What should your team grant to Engineering Group A to meet this requirement?

  • A. Compute Network User Role at the host project level.
  • B. Compute Network User Role at the subnet level.
  • C. Compute Shared VPC Admin Role at the host project level.
  • D. Compute Shared VPC Admin Role at the service project level.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mozammil89
Highly Voted 4 years, 8 months ago
The correct answer is B. https://cloud.google.com/vpc/docs/shared-vpc#svc_proj_admins
upvoted 22 times
...
okhascorpio
Most Recent 9 months, 1 week ago
Selected Answer: A
A is right. Source: https://cloud.google.com/compute/docs/access/iam#compute.networkUser
upvoted 1 times
stefanop
4 months, 2 weeks ago
this permission can be granted only at project level, not subnet level
upvoted 1 times
...
...
ErenYeager
9 months, 2 weeks ago
Selected Answer: B
B) Compute Network User Role at the subnet level. The key points: In a Shared VPC, the subnets are configured in the host project. To allow another project to use a specific subnet, grant the Compute Network User role on that subnet. The Compute Shared VPC Admin role allows full administration, which is more privileged than needed. The Compute Network User role at the project level allows accessing all subnets, not just 10.1.1.0/24. So granting the Compute Network User role specifically on the 10.1.1.0/24 subnet gives targeted access to only that subnet, meeting the requirement. The subnet-level Compute Network User role provides the minimum necessary access to fulfill the need for Engineering Group A.
upvoted 4 times
...
Xoxoo
1 year, 2 months ago
Selected Answer: B
To enable Engineering Group A to attach a Compute Engine instance to only the 10.1.1.0/24 subnet in a Shared VPC setup, you should follow these steps: Grant the Compute Network User role at the service project level: This will allow members of Engineering Group A to create Compute Engine instances in their respective service projects. Grant the Compute Network User role specifically on the 10.1.1.0/24 subnet: To ensure that Engineering Group A can only attach instances to the desired subnet, you should grant the Compute Network User role directly at the subnet level. This way, they have the necessary permissions for that specific subnet without impacting other subnets in the Shared VPC. Option B, "Compute Network User Role at the subnet level," is the most appropriate choice in this scenario to achieve the desired outcome.
upvoted 3 times
...
shetniel
1 year, 2 months ago
The correct answer is B per least privilegd access rule
upvoted 2 times
...
[Removed]
1 year, 4 months ago
Selected Answer: B
"B" seems to be the most appropriate answer. See step 4 here: https://medium.com/google-cloud/google-cloud-shared-vpc-b33e0c9dd320
upvoted 2 times
...
aashissh
1 year, 7 months ago
Selected Answer: B
To enable Engineering Group A to attach a Compute Engine instance to only the 10.1.1.0/24 subnet in a Shared VPC Network where project co-vpc-prod is the host project, your team should grant Compute Network User Role at the subnet level. This will allow Engineering Group A to create and manage resources in the specified subnet while restricting them from making changes to other resources in the host project. Granting Compute Network User Role at the host project level would allow Engineering Group A to create and manage resources across all subnets in the host project, which is more than what is needed in this case. Compute Shared VPC Admin Role at either the host or service project level would give Engineering Group A too much control over the Shared VPC Network.
upvoted 2 times
...
mahi9
1 year, 9 months ago
Selected Answer: B
Admin role is not required
upvoted 2 times
...
Olen93
1 year, 9 months ago
The correct answer is B - https://cloud.google.com/compute/docs/access/iam#compute.networkUser states that the lowest level it can be granted on is project however I did confirm on my own companies shared VPC that roles/compute.networkUser can be granted at the subnet level
upvoted 1 times
...
amanp
1 year, 9 months ago
Selected Answer: A
Answer is A not B The least level the Compute Network User role can be assigned is at Project level and NOT subnet level. https://cloud.google.com/compute/docs/access/iam#compute.networkUser
upvoted 2 times
...
Meyucho
2 years ago
Selected Answer: B
Grant network.user at subnet level: https://cloud.google.com/vpc/docs/provisioning-shared-vpc#networkuseratsubnet
upvoted 2 times
...
AwesomeGCP
2 years, 1 month ago
Selected Answer: B
The correct answer is B. https://cloud.google.com/vpc/docs/shared-vpc#svc_proj_admins
upvoted 2 times
...
rajananna
2 years, 1 month ago
Selected Answer: A
Lowest level grant is at Project level. https://cloud.google.com/compute/docs/access/iam#compute.networkUser
upvoted 2 times
Premumar
2 years, 1 month ago
Lowest level grant is at Subnet level in this option. Project level is a broad level access.
upvoted 2 times
...
...
tangac
2 years, 2 months ago
Selected Answer: A
based on that documentation it should clearly be done at the host project level : https://cloud.google.com/compute/docs/access/iam#compute.networkUser
upvoted 3 times
...
piyush_1982
2 years, 4 months ago
Selected Answer: B
https://cloud.google.com/vpc/docs/shared-vpc#svc_proj_admins
upvoted 1 times
...
Medofree
2 years, 7 months ago
Selected Answer: B
The correct answer is b
upvoted 2 times
...
droppler
3 years, 4 months ago
The right one is b on my thinking, but i need to enable the other team to do the jobs, falls into D
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...