As project owner, you want to delegate bucket and object management to colleagues following Google recommendations. Which IAM role should you grant?
Choose an answer
Tap an option to check your answer.
Correct answer: Storage Admin.
Why this is the answer
The Storage Admin role (roles/storage.admin) grants full control over Cloud Storage buckets and objects, including creating, deleting, and modifying both. This aligns with the project owner's need to delegate comprehensive bucket and object management. Project Editor (roles/editor) grants broad edit access across most Google Cloud resources, but it's overly permissive for just storage management and doesn't follow the principle of least privilege. Storage Object Admin (roles/storage.objectAdmin) allows full control over objects but not buckets, meaning colleagues couldn't create or delete buckets. Storage Object Creator (roles/storage.objectCreator) only allows creating objects, not managing existing ones or buckets, which is too restrictive for the stated goal.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed