exam questions

Exam Professional Cloud Network Engineer All Questions

View all questions & answers for the Professional Cloud Network Engineer exam

Exam Professional Cloud Network Engineer topic 1 question 11 discussion

Actual exam question from Google's Professional Cloud Network Engineer
Question #: 11
Topic #: 1
[All Professional Cloud Network Engineer Questions]

You are trying to update firewall rules in a shared VPC for which you have been assigned only Network Admin permissions. You cannot modify the firewall rules.
Your organization requires using the least privilege necessary.
Which level of permissions should you request?

  • A. Security Admin privileges from the Shared VPC Admin.
  • B. Service Project Admin privileges from the Shared VPC Admin.
  • C. Shared VPC Admin privileges from the Organization Admin.
  • D. Organization Admin privileges from the Organization Admin.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ss_1982
Highly Voted 4 years, 2 months ago
Answer is A: A Shared VPC Admin can define a Security Admin by granting an IAM member the Security Admin (compute.securityAdmin) role to the host project. Security Admins manage firewall rules and SSL certificates.
upvoted 18 times
AzureDP900
1 year, 11 months ago
Agreed
upvoted 1 times
...
...
saraali
Most Recent 2 months, 2 weeks ago
Selected Answer: A
The correct answer is A. Security Admin privileges from the Shared VPC Admin. Since you currently have Network Admin permissions, which do not allow modification of firewall rules, you should request Security Admin privileges. This will give you the necessary permissions to manage and update firewall rules in the Shared VPC while following the least privilege principle. This ensures that you have just the required level of access without unnecessary permissions.
upvoted 1 times
...
DMPKS
3 months, 3 weeks ago
Selected Answer: B
Service Project Admin privileges provide you with the necessary permissions to manage resources within a service project, including managing firewall rules associated with that project. This adheres to the least privilege principle because you're only requesting the minimal set of permissions to manage firewall rules within your assigned service project.
upvoted 1 times
...
xhilmi
10 months, 3 weeks ago
Selected Answer: A
Choose option A. Explanation: Security Admin Role: The Security Admin role is specific to managing firewall rules and network-related permissions within a project. It allows you to manage firewall rules, among other network-related configurations. Shared VPC Admin: Shared VPC Admin has broader permissions, including the ability to manage shared VPC configurations, but it may grant more permissions than necessary for managing firewall rules. Options B, C, and D provide broader permissions than necessary for the task of updating firewall rules within a shared VPC: Therefore, option A is the most specific and least privileged option for managing firewall rules within the shared VPC context.
upvoted 1 times
...
pk349
1 year, 9 months ago
A: Security Admin ******* • IAM principal in the host project, or • IAM principal in the organization A Shared VPC Admin can define a Security Admin by granting an IAM principal the Security Admin (compute.securityAdmin) role to the host project. Security Admins manage firewall rules and SSL certificates.
upvoted 1 times
...
shayanahmed
1 year, 9 months ago
Selected Answer: A
Answer is A
upvoted 1 times
...
GCP72
2 years, 2 months ago
Selected Answer: A
Answer should be A
upvoted 2 times
...
kumarp6
2 years, 9 months ago
Answer is A
upvoted 3 times
...
desertlotus1211
2 years, 11 months ago
Answer is A: https://cloud.google.com/vpc/docs/shared-vpc#net_and_security_admins it's states: 'A Shared VPC Admin can define a Security Admin by granting an IAM principal the Security Admin (compute.securityAdmin) role to the host project. Security Admins manage firewall rules and SSL certificates.'
upvoted 2 times
...
[Removed]
3 years, 11 months ago
Ans - A
upvoted 1 times
...
beebee
4 years, 3 months ago
Should be A
upvoted 1 times
...
dg63
4 years, 3 months ago
"A" - based on least privilege approach
upvoted 3 times
Darius_Th3D0G
4 years, 3 months ago
Yes, it's A. https://cloud.google.com/vpc/docs/shared-vpc#net_and_security_admins
upvoted 2 times
...
...
Supernhi
4 years, 3 months ago
https://cloud.google.com/vpc/docs/shared-vpc . It's B
upvoted 2 times
desertlotus1211
2 years, 11 months ago
Service Project Admins are only given the ability to create and manage instances that make use of the Shared VPC network
upvoted 1 times
desertlotus1211
2 years, 11 months ago
Answer is not B....
upvoted 1 times
...
...
...
Jos
4 years, 4 months ago
A "shared VPC admin", not clear what that could be :), cannot give that kind of permissions. It's D for me.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago