Given IAM policies set at organization, folder, and project levels, what is the effective IAM policy at a node in the resource hierarchy?
Choose an answer
Tap an option to check your answer.
Correct answer: The effective policy is the union of the policy set at the node and policies inherited from its ancestors.
Why this is the answer
The correct answer is that the effective policy is the union of the policy set at the node and policies inherited from its ancestors. This is because IAM policies in Google Cloud are inherited hierarchically. A resource inherits all policies from its parent, and these inherited policies are combined with any policies directly applied to the resource. This combination is a union, meaning that if a permission is granted at a higher level, it applies to all child resources, even if not explicitly granted at the child level. Conversely, permissions granted at a child level only apply to that child and its descendants. The other options are incorrect because policies are not restricted by ancestors (they are inherited), nor is it only determined by the node itself, and it's a union, not an intersection, of permissions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed