New user must be able to update a VPC firewall rule and view firewall logs. Which IAM roles and firewall priority should you assign/apply?
Choose an answer
Tap an option to check your answer.
Correct answer: Assign roles compute.securityAdmin and logging.viewer to the user. Apply the new firewall rule with priority 50..
Why this is the answer
The compute.securityAdmin role grants permissions to manage firewall rules, including creation, modification, and deletion, satisfying the requirement to update a VPC firewall rule. The logging.viewer role allows the user to view logs, including firewall logs, fulfilling the second requirement. Firewall rules are evaluated by priority, with lower numerical values indicating higher priority. Applying the new firewall rule with priority 50 ensures it is evaluated before rules with higher priority numbers (e.g., 150), which is often desired for specific, overriding rules. logging.bucketWriter is incorrect as it grants write access to logs, not view access. compute.orgSecurityPolicyAdmin is for managing organization-level security policies, not VPC firewall rules.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed