DevOps needs access to production services. To avoid future Google product changes broadening their permissions and follow best practices, what should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a custom role with the required permissions and grant it to the DevOps team on the production project..
Why this is the answer
Creating a custom role with only the necessary permissions and granting it at the production project level adheres to the principle of least privilege. This ensures that the DevOps team has precisely what they need without excessive access, which minimizes the security risk of over-permissioning. It also protects against future Google product changes that might inadvertently broaden permissions of predefined roles. Granting the Project Editor role at the organization or project level provides broad, unnecessary permissions, violating the principle of least privilege. Granting a custom role at the organization level is also too broad, as it would apply to all projects, not just the production one.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed