Require identical developer permissions across projects limited to Compute Engine, Cloud Functions, and Cloud SQL with minimal effort. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Add all developers to a Google Group in Cloud Identity, create a custom role with Compute Engine, Cloud Functions, and Cloud SQL permissions at the organization level, and assign the custom role to the group..
Why this is the answer
Creating a custom role at the organization level allows you to define the exact permissions needed (Compute Engine, Cloud Functions, Cloud SQL) once and apply it consistently across all projects. Assigning this custom role to a Google Group (managed in Cloud Identity) means you manage developer access centrally; adding or removing a developer from the group automatically updates their permissions across all projects, minimizing effort. The other options are less efficient: Copying a custom role per project (option 1) requires manual effort for each project and doesn't centralize permission definition. Assigning the predefined Compute Admin role at the organization level (option 2) grants excessive permissions beyond what's required for Cloud Functions and Cloud SQL, violating the principle of least privilege. Assigning multiple predefined roles per project (option 3) is repetitive and doesn't allow for the precise, combined permissions specified.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed