Organization has Finance and Shopping folders. A dev-team Google Group is granted Project Owner at the Organization level. You must prevent the dev group from creating resources under the Finance folder. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Grant the dev group Project Owner on the Shopping folder and remove the dev group's Project Owner binding at the Organization level..
Why this is the answer
The correct solution is to remove the dev group's Project Owner binding at the Organization level and then grant them Project Owner on the Shopping folder. IAM policies are inherited down the resource hierarchy. If the dev group has Project Owner at the Organization level, they implicitly have owner permissions on all folders and projects within that organization, including the Finance folder. To restrict their access to Finance, the broad organizational permission must be removed. Then, specific Project Owner access can be granted to the Shopping folder. Granting Project Viewer on Finance (incorrect option 1 & 2) would not override the Organization-level Project Owner role, as Project Owner is a more permissive role. Granting Project Owner only on Shopping (incorrect option 4) without removing the Organization-level role would still leave them as owners of the Finance folder.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed