You have Network Admin on a Shared VPC but cannot modify firewall rules. Following least-privilege principles, which role should you request to update firewall rules?
Choose an answer
Tap an option to check your answer.
Correct answer: Security Admin privileges from the Shared VPC Admin..
Why this is the answer
The correct answer is Security Admin privileges from the Shared VPC Admin. To modify firewall rules in a Shared VPC, you need the compute.securityAdmin role. This role grants permissions specifically for managing firewall rules, SSL policies, and other network security settings, aligning with the principle of least privilege. This role must be granted by the Shared VPC Admin (project owner of the host project) because firewall rules are defined at the host project level and apply across all attached service projects. Service Project Admin privileges are insufficient because firewall rules are managed at the host project level, not within individual service projects. Shared VPC Admin privileges are too broad; while they can grant the necessary role, requesting the full Shared VPC Admin role violates least privilege if only firewall modification is needed. Organization Admin privileges are far too extensive and grant control over the entire Google Cloud organization, which is unnecessary and insecure for this task.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed