A platform team needs to grant a contractor ability to create and modify VPC networks, subnets, Cloud Routers, and Cloud NATs, but not change IAM or billing. Which predefined IAM role should they grant at the project level to follow least privilege?
Choose an answer
Tap an option to check your answer.
Correct answer: Compute Network Admin (roles/compute.networkAdmin).
Why this is the answer
The Compute Network Admin role (roles/compute.networkAdmin) is the most appropriate choice because it grants permissions to manage all network-related resources, including VPC networks, subnets, Cloud Routers, and Cloud NATs, without providing broader administrative access. This aligns with the principle of least privilege, ensuring the contractor only has necessary permissions. Organization Admin (roles/resourcemanager.organizationAdmin) is incorrect as it grants extensive control over the entire Google Cloud organization, far exceeding the required permissions. Compute Admin (roles/compute.admin) is too broad, providing full control over Compute Engine resources, not just networking. Project Editor (roles/editor) is also too broad, granting read/write access to most resources within a project, including the ability to manage IAM and billing, which the question explicitly states should be restricted.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed