New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Professional Cloud Architect Exam - Topic 12 Question 12 Discussion

Actual exam question for Google's Professional Cloud Architect exam
Question #: 12
Topic #: 12
[All Professional Cloud Architect Questions]

Your company is using Google Cloud. You have two folders under the Organization: Finance and Shopping. The members of the development team are in a Google Group. The development team group has been assigned the Project Owner role on the Organization. You want to prevent the development team from creating resources in projects in the Finance folder. What should you do?

Show Suggested Answer Hide Answer
Suggested Answer: C

https://cloud.google.com/resource-manager/docs/cloud-platform-resource-hierarchy

'Roles are always inherited, and there is no way to explicitly remove a permission for a lower-level resource that is granted at a higher level in the resource hierarchy. Given the above example, even if you were to remove the Project Editor role from Bob on the 'Test GCP Project', he would still inherit that role from the 'Dept Y' folder, so he would still have the permissions for that role on 'Test GCP Project'.'


Contribute your Thoughts:

0/2000 characters
Kami
4 months ago
I’m not sure about D, seems risky to keep them as Owners anywhere!
upvoted 0 times
...
Trinidad
4 months ago
A is a solid approach, but I’d go with C for more control.
upvoted 0 times
...
Edda
4 months ago
Wait, can they really create resources if they have Owner on Shopping?
upvoted 0 times
...
Magnolia
4 months ago
I think C is the best choice, removing the Org role is key.
upvoted 0 times
...
Noel
5 months ago
Option B seems right, just give them Project Viewer for Finance.
upvoted 0 times
...
Lavina
5 months ago
I’m leaning towards option C because it seems like the safest way to ensure they can't create anything in Finance while keeping their access to Shopping.
upvoted 0 times
...
Valentin
5 months ago
I feel like option B could work, but it seems too simple. What if they still have some permissions that allow them to create resources?
upvoted 0 times
...
Gail
5 months ago
I remember a practice question where we had to manage roles at different levels, and I think removing the Project Owner role from the Organization might be key here.
upvoted 0 times
...
Eric
5 months ago
I think we need to limit their permissions specifically for the Finance folder, but I'm not sure if just assigning them Project Viewer is enough.
upvoted 0 times
...
Garry
5 months ago
This looks like a straightforward question about state machine transitions. I'll carefully review the options and choose the four that seem most likely to be valid substates of Retired.
upvoted 0 times
...
Krystina
5 months ago
Hmm, I'm not entirely sure about this one. I'll need to review the SteelCentral NPM architecture details to make sure I understand which component is responsible for that functionality.
upvoted 0 times
...

Save Cancel