Add a new auditor who needs read-only access to all items in a GCP project. How should you assign permissions?
Choose an answer
Tap an option to check your answer.
Correct answer: Select the built-in IAM project Viewer role. Add the user's account to this role..
Why this is the answer
The built-in IAM Project Viewer role (roles/viewer) grants read-only access to all resources within a GCP project, which perfectly aligns with the requirement for an auditor needing to view all items. This is the most straightforward and secure method. Creating a custom role is unnecessary here because a suitable built-in role already exists. Custom roles are best used when granular permissions not covered by built-in roles are needed. There is no "view-only service permissions" or "service Viewer role" that applies universally across all services in a project; roles are typically defined at the project, folder, or organization level, or for specific services.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed