External auditor must be able to view all resources in a project, but Organization Policy Domain Restricted Sharing limits accounts to your Cloud Identity domain. Provide the auditor read-only access.
Choose an answer
Tap an option to check your answer.
Correct answer: Create a temporary Cloud Identity account for the auditor and grant that account the Viewer role on the project..
Why this is the answer
The correct approach is to create a temporary Cloud Identity account for the auditor and grant it the Viewer role. This is because the Organization Policy Domain Restricted Sharing prevents external Google accounts from accessing resources. A Cloud Identity account within your domain bypasses this restriction. The Viewer role provides read-only access to all resources, satisfying the requirement for the auditor to view everything without making changes. Granting the Security Reviewer role is incorrect because, while it offers read-only access, it's specifically designed for security-related insights and logs, not general resource viewing. Asking for the auditor's existing Google account is incorrect because the domain restriction policy would prevent access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed