Be able to determine effective access by evaluating IAM allow policies, deny policies, and Organization Policy constraints across the resource hierarchy. The most critical skill is knowing that deny policies override allows, and that constraints like iam.disableServiceAccountKeyCreation prevent key creation regardless of IAM permissions.
Start practicing
Configuring Access Within a Cloud Solution Environment — choose a session length
Free · No account required
Domain overview
This domain covers designing and enforcing access control in Google Cloud using IAM policies, roles, and Organization Policy constraints. It tests how principals inherit permissions across resource hierarchy, how deny policies override allows, and how to restrict service usage. Expect scenario questions on troubleshooting access failures, custom roles, and organization policy constraints.
Exam objectives
Resolving effective permissions from IAM allow and deny policies across resource hierarchy.
Creating custom IAM roles with required permissions like iam.roles.create.
Applying Organization Policy constraints such as iam.disableServiceAccountKeyCreation.
Understanding folder-level policies and their impact on project creation and service usage.
Assuming folder-level IAM grants override project-level deny policies; deny always takes precedence.
Forgetting that custom role creation requires iam.roles.create on the parent resource, not just project-level permissions.
Confusing Organization Policy constraints with IAM roles; constraints restrict resource configurations, not direct permissions.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An organization uses Active Directory (AD) on-premises and wants to synchronize user accounts and groups to Google Cloud Identity for SSO with SAML 2.0. The AD contains 50,000 users and 10,000 groups. The solution must support automatic provisioning and deprovisioning of users. Which tool should they use?
2A developer wants to grant a Compute Engine instance access to read objects from a Cloud Storage bucket. The instance runs under a service account. What is the best practice for granting this access?
3What is the purpose of Identity-Aware Proxy (IAP) on Google Cloud?
4A DevOps team uses GitHub Actions to deploy infrastructure to Google Cloud. They want to avoid storing long-lived service account keys. Which approach should they use to authenticate from GitHub Actions to Google Cloud?
5A company wants to use Google Cloud resources but does not have a Google Workspace or Cloud Identity account. They want to manage identities for their users without paying for additional licenses. What is the most cost-effective identity solution?
6A developer needs to create a custom IAM role that allows only a specific set of permissions for managing Cloud SQL instances. The role should be available at the organization level. Which command should they use?
7A security administrator wants to prevent users from disabling Shielded VM on existing Compute Engine instances. Which IAM permission should they deny?
8A financial services company is migrating to Google Cloud and needs to enforce strict security controls. They want to ensure that: 1) No service account keys are created. 2) All Compute Engine instances must be created with Shielded VM enabled. 3) Only users from the corporate domain (example.com) can be granted IAM roles. Which THREE Organization Policy constraints must be used? (Choose three.)
9A company wants to allow an external auditor to view all IAM policies in a project but not modify them. The auditor's Google account is from a different domain. Which IAM role should be assigned?
10A DevOps engineer needs to create a custom IAM role that allows creating and deleting Compute Engine instances but not stopping or starting them. Which permissions should be included?
11Which of the following is true about IAM deny policies?
12A company uses Cloud Identity to manage users and groups. They want to synchronize users from their on-premises Active Directory to Cloud Identity. Which tool should they use?
13A GKE cluster runs workloads that need to access Cloud Storage. The security team wants to avoid using service account keys and ensure each pod has a unique identity. What is the best practice?
14An organization wants to allow users to access a web application running on Compute Engine via HTTPS. The application requires users to authenticate with their corporate credentials (SAML 2.0 IdP). Which Google Cloud service should be used?
15A company wants to enforce that only users from a specific domain (example.com) can be granted IAM roles on any resource in their organization. Which two steps are required? (Choose two.)
16A security engineer needs to ensure that all Compute Engine instances in an organization are created with specific CMEK (Customer-Managed Encryption Key) for disk encryption. The engineer wants to enforce this at the organization level. Which three actions are required? (Choose three.)
17A developer wants to allow a CI/CD pipeline running on GitHub Actions to deploy resources to a GCP project without using service account keys. Which two components are needed? (Choose two.)
18An organization uses Cloud Identity with a third-party IdP via SAML 2.0. A security engineer needs to enforce that all Google Cloud access requires multi-factor authentication (MFA) from the IdP. What is the recommended approach?
19A developer wants to run a containerized application on GKE that needs to read from a Cloud Storage bucket. The developer needs to securely provide credentials. What is the recommended approach?
20An application running on Compute Engine needs to authenticate to Google Cloud APIs. The security engineer wants to avoid managing keys. What is the recommended method?
21A company needs to allow developers to create and manage custom IAM roles at the project level, but restrict the permissions that can be added to those roles to a predefined list. What should be used?
22A security engineer needs to configure Identity-Aware Proxy (IAP) for a web application running on Compute Engine. The goal is to ensure that only authenticated users from the corporate domain can access the application. What is the first step in the configuration?
23A security engineer needs to ensure that no one in the organization can disable or delete Cloud Key Management Service (Cloud KMS) keys, except for a designated security team. Which TWO approaches should be combined? (Choose 2 correct answers)
24A security engineer wants to ensure that no IAM keys are created for service accounts in a Google Cloud organization. Which organization policy constraint should be applied?
25A DevOps engineer wants to allow a CI/CD pipeline running in GitHub Actions to deploy resources to a Google Cloud project without using long-lived service account keys. What should the engineer implement?
26Which IAM role should be assigned to a user who needs to manage Cloud Storage objects in a specific project, but should not be able to create or delete buckets?
27An organization uses Cloud Identity with Google Workspace. They want to grant a group of external auditors read-only access to a specific folder in Google Cloud. The auditors have accounts in the organization's Cloud Identity domain. What is the most efficient way to grant this access?
28A company has a Kubernetes cluster on GKE that runs a microservice. The microservice needs to read from a Cloud Spanner database. The security team requires that the microservice uses the principle of least privilege and that credentials are never stored as Kubernetes secrets. What is the recommended configuration?
29A company wants to allow users to access an internal web application running on Compute Engine behind a load balancer without requiring a VPN. The solution must authenticate users and enforce access based on user identity and context (e.g., device security). Which Google Cloud service should they use?
30A company has an organization policy that denies the use of certain GCP services unless the project is in a specific folder. The DevOps team wants to create a new project in that folder. However, the project creation fails. What is the most likely cause?
31A security engineer notices that a service account has been assigned the roles/iam.serviceAccountUser role at the project level. What actions can a user with this role perform?
32A company wants to implement single sign-on (SSO) for its employees to access the Google Cloud Console using their existing corporate credentials from an on-premises Active Directory. Which THREE components are required? (Choose 3)
33An organization has multiple GCP projects managed through folders in the resource hierarchy. They want to enforce a policy that prohibits the creation of service account keys across all projects. Which approach should be used?
34A developer is running a batch job on Compute Engine that needs to read data from Cloud Storage. What is the recommended way to authenticate the VM to Cloud Storage without managing keys?
35An organization wants to allow an external identity provider (IdP) that supports OpenID Connect (OIDC) to access GCP resources. They want to avoid creating and managing service account keys. What should they use?
36A Google Kubernetes Engine (GKE) cluster has applications that need to access Cloud Storage. The security team wants to grant fine-grained access per pod. What is the recommended approach?
37An organization uses Cloud Identity to manage users and groups. They want to enforce that only users from their corporate domain (example.com) can be granted IAM roles on GCP resources. Which organization policy constraint should they use?
38What is the purpose of Identity-Aware Proxy (IAP) in Google Cloud?
39A company wants to allow an application running on an on-premises server to access Cloud Storage without using long-lived service account keys. The on-premises environment uses Azure Active Directory (Azure AD) as its identity provider. Which GCP feature should they use?
40A company wants to enforce that no service account keys are created for service accounts in a specific project. Additionally, they want to allow only users from their corporate domain (example.com) to be granted IAM roles. Which TWO organization policy constraints should they apply at the project level?
41A security team needs to allow a third-party application running on AWS to access a Cloud Storage bucket without using service account keys. The application already uses AWS IAM roles. Which Google Cloud feature should they use?
42A company has a security policy that service account keys should not be created. They want to prevent anyone from creating keys for any service account in the organization. Which organization policy constraint should they use?
43An organization has a deny policy that denies the compute.instances.create permission for all principals on a folder. A user is granted the Compute Admin role (which includes compute.instances.create) at the project level within that folder. Can the user create Compute Engine instances in that project?
44A company wants to allow their employees to access an internal web application running on Compute Engine using Identity-Aware Proxy (IAP). They want to ensure that only users from their corporate domain (example.com) can access the app. What is the recommended approach?
45A developer wants to grant a service account the ability to impersonate another service account in a different project. Which IAM permission is required for the developer to assign?
46A company wants to enforce that all Compute Engine instances are created with a specific set of tags for compliance. They also want to audit any changes to firewall rules. Which two Google Cloud services or features should they use? (Choose TWO.)
47A company wants to implement a zero-trust access model for SSH access to Compute Engine instances. They need to ensure that only authorized users can connect and that all connections are logged. Which two services should they use? (Choose TWO.)
48A developer needs to deploy a web application on Compute Engine that must access Cloud Storage buckets. The best practice for providing credentials to the VM is to:
49A company uses Google Workspace and wants to allow users to authenticate to a third-party SaaS application using their Google credentials. The SaaS application supports SAML 2.0. What should the administrator configure?
50An organization has a deny policy at the folder level that denies the permission resourcemanager.projects.create. A user has an allow policy at the project level granting roles/owner. What is the effective permission for the user to create projects in that project?
51Which of the following is a benefit of using organization policies over IAM policies for enforcing restrictions on resources?
52A company wants to provide their employees access to a web application running on Compute Engine without exposing the VM to the public internet. The application uses a custom header to verify the user's identity. Which service should they use?
53An organization wants to grant a CI/CD pipeline (running on GitHub Actions) access to deploy resources in a GCP project without storing long-lived service account keys. Which approach is recommended?
54A security team wants to enforce that all Compute Engine instances in the organization use Shielded VM features (Secure Boot, vTPM, Integrity Monitoring). What should they configure?
55A user in a Google Cloud organization wants to create a custom IAM role at the project level. Which permission is required to create custom roles?
56A company wants to allow their on-premises Active Directory users to access Google Cloud resources using their existing credentials. They need to synchronize user accounts and groups to Google Cloud Directory and enable federated authentication. Which TWO services should they use?
57A security engineer needs to ensure that a specific Compute Engine instance can only be accessed via HTTPS from users authenticated through Cloud Identity. The instance is behind an HTTP(S) load balancer. What should the engineer configure on the load balancer to enforce this access control?
58Your organization wants to assign a set of permissions to a group of users that allows them to create and delete Compute Engine instances, but not to modify other resources like Cloud Storage buckets. Which type of IAM role should you create?
59A company wants to allow an application running in an on-premises data center to access Google Cloud Storage buckets without storing long-lived service account keys. The on-premises application authenticates using an external identity provider (IdP) that supports OpenID Connect (OIDC). Which Google Cloud feature should they use?
60A DevOps engineer needs to allow a CI/CD pipeline running in Google Kubernetes Engine (GKE) to push images to a specific Artifact Registry repository. The pipeline uses a Kubernetes service account. What is the best practice to grant this access without creating a JSON key for a Google service account?
61Your organization uses Cloud Identity with SAML 2.0 federation from an external identity provider (IdP). You need to ensure that only users from a specific group in the IdP can access a critical application behind an HTTPS load balancer. Which combination of steps is required?
62A company has an organization policy that disables service account key creation (constraints/iam.disableServiceAccountKeyCreation). However, a legacy application requires a service account key to authenticate. What should the engineer do to satisfy this requirement while following best practices?
63Which of the following is the correct order of the Google Cloud resource hierarchy from highest to lowest?
64An organization uses Cloud Identity with SAML 2.0 federation. They want to enable single sign-on (SSO) for users accessing Google Cloud Console and also allow access to a custom application behind an HTTPS load balancer using IAP. Which TWO configurations are required? (Choose two.)
65Your organization has an IAM policy at the folder level that grants a user the Compute Admin role. A deny policy at the project level denies the same user the compute.instances.create permission. What is the effective access for this user on the project?
66A security engineer needs to enforce that all Compute Engine VMs in an organization use Shielded VM features. Which approach should they use?
67A company uses Google Cloud Directory Sync to synchronize users from an on-premises Active Directory to Cloud Identity. They want to allow federated access from their external identity provider (IdP) that supports SAML 2.0. The IdP should be able to authenticate users from a specific AD domain. What configuration steps are required?
68A DevOps team wants to grant a CI/CD pipeline (running on a Compute Engine VM) the ability to restart Compute Engine instances in a specific project. The VM has a service account attached. What is the best practice to grant this permission?
69A company is migrating to Google Cloud and wants to implement least privilege access for their engineers. They have the following requirements: 1) Engineers must be able to create and manage Cloud Storage buckets. 2) Engineers must NOT be able to delete any resources. 3) Engineers should not be granted basic roles. Which two predefined roles should they combine to meet these requirements? (Choose two.)
70A company wants to implement workload identity federation for a GitHub Actions workflow, allowing it to access Google Cloud resources without using service account keys. Which three steps are required? (Choose three.)
71A company wants to use Google Cloud Directory Sync (GCDS) to synchronize users and groups from an on-premises Active Directory to Cloud Identity. Which two prerequisites must be met? (Choose two.)
72A company has an application running on a Compute Engine VM that needs to call the Cloud Vision API. The security team mandates that no long-lived service account keys be created. They also require that the VM's outbound traffic is not blocked by a firewall rule denying egress to metadata.google.internal. Which approach should the security engineer use?
73A security engineer must ensure that a service account used by an application on Compute Engine can only access a specific Cloud Storage bucket named 'prod-data' and no other buckets in the project. The service account currently has the roles/storage.objectViewer role granted at the project level. What should the engineer do to meet this requirement?
74A security engineer must grant a data-analytics team the ability to run BigQuery jobs in project analytics-prod. The team's members are managed in a Google Group, but several members also need the same capability in project analytics-dev. The engineer wants a single, auditable binding that applies only to BigQuery job execution and nothing else. Which approach should the engineer take?
75Your organization uses Google Cloud with a folder hierarchy. You need to grant a data engineering team the ability to create and manage Cloud Storage buckets in all current and future projects under the folder 'analytics'. The team should not have any permissions in other folders. What should you do?
76A company uses Google Cloud Directory Sync (GCDS) to synchronize users from an on-premises Active Directory to Cloud Identity. They want to ensure that when an employee is terminated in Active Directory, their Google Cloud access is revoked within 15 minutes. What should they configure?
77A security team wants to enforce that no user in the organization can modify the retention policy on any Cloud Storage bucket, even if they have the storage.buckets.update permission. They need a centralized, organization-wide policy that overrides any allow policies. What should they do?
78A security engineer is configuring a service account for a Compute Engine instance that will run a batch job. The job needs to read objects from a Cloud Storage bucket in the same project. The engineer wants to follow the principle of least privilege and avoid managing long-lived keys. Which approach should the engineer take?
79A financial services company runs workloads in a Shared VPC host project. A security engineer must let a service account in a service project attach a new VM to a subnet in the host project, but must not allow that service account to modify the subnet or firewall rules. Which combination of grants achieves this?
80A company uses Google Cloud and wants to allow their data scientists to access BigQuery datasets only from corporate-owned devices. They use BeyondCorp Enterprise and have device posture information available. What should they configure to enforce this access control?
81A security engineer is configuring IAM policies for a project that contains sensitive data. The engineer needs to ensure that a specific group of users cannot access Cloud Storage objects in the project, even if they are granted a role that would otherwise allow it. The engineer wants to use an IAM deny policy to enforce this restriction. Which of the following is true about the scope of an IAM deny policy?
82A company uses Google Cloud and wants to allow their data scientists to access BigQuery datasets but only from corporate devices that meet specific security requirements (e.g., disk encryption enabled, screen lock enforced). The data scientists authenticate with their Google Workspace accounts. What should the security engineer implement?
83An organization uses Google Cloud and wants to enforce that all access to BigQuery datasets must be approved by a manager. The security team wants to implement a just-in-time (JIT) access solution that grants temporary permissions. They also want to log all access attempts. Which combination of Google Cloud services should they use?
84A platform team is configuring Cloud IAM Conditions to limit when members of a Google Group can act as service accounts. They want the condition to be evaluated reliably and to avoid silently blocking legitimate automation. Which two statements about IAM Conditions are accurate? (Choose two.)
85A financial institution uses Google Cloud and wants to ensure that only service accounts within a specific project can impersonate a critical service account used by a payment processing application. They need to grant the `iam.serviceAccounts.getAccessToken` permission to allow impersonation. Which IAM role should they grant to the authorized service accounts?
86A security team is reviewing IAM policies for a project that hosts a web application on Compute Engine. They want to grant a new service account the ability to write logs to Cloud Logging and publish messages to a Pub/Sub topic. They also want to follow the principle of least privilege. Which two predefined IAM roles should they grant to the service account? (Choose two.)
87A security engineer needs to grant a service account the ability to read objects from a specific Cloud Storage bucket, but must ensure that the service account cannot delete or overwrite any objects. The service account is used by an application running on Compute Engine. Which IAM role should be granted on the bucket?
88A security administrator needs to let a support team troubleshoot production VMs without granting them SSH keys or external IP access. The team should connect through Google Cloud's proxy and have their sessions recorded for audit. Which configuration should the administrator implement?
89A company has an organization policy that enforces `constraints/iam.disableServiceAccountKeyCreation` at the organization level. A developer needs to deploy a workload on a Compute Engine instance that requires access to Cloud Storage. They cannot create a service account key. What is the recommended way to grant the instance access to Cloud Storage?
90A company has an organization policy that requires all service accounts to be created with a specific naming prefix. A security engineer needs to enforce this automatically. What should they do?
91A security team manages a project containing sensitive Compute Engine instances and Cloud Storage buckets. They need to grant a new data analyst read-only access to only the Cloud Storage buckets in the project, while explicitly preventing any access to Compute Engine resources. The analyst authenticates with a Google Workspace account. Which IAM configuration should the team implement?
92A security engineer needs to allow a group of data scientists to access BigQuery datasets in a project. The data scientists authenticate with Google Workspace accounts and are members of a Google Group. The engineer wants to grant them the minimum permissions necessary to query data and view dataset metadata, but not to modify or delete datasets. They also want to ensure that if a new data scientist joins the group, they automatically receive access. What should the engineer do?
93A security engineer is configuring IAM policies for a project that hosts sensitive data. They need to ensure that IAM roles are granted according to least privilege and that access is auditable. Which two practices should they follow? (Choose two.)
94A company has an organization policy that enforces the 'Disable service account key creation' constraint. A developer needs to deploy a workload on Compute Engine that requires access to Cloud Storage. The developer wants to avoid using service account keys. What should the developer do to allow the Compute Engine instance to access Cloud Storage securely?
95A platform team manages a shared VPC host project. They need to allow a group of network administrators to create and manage firewall rules in the host project, but they must not be able to modify any other network resources. Which IAM role should be granted at the host project level?
96A security administrator is configuring Google Cloud Identity-Aware Proxy (IAP) to protect an internal application running on Compute Engine. They want to ensure that only users from a specific Google Workspace domain and with a specific device posture can access the application. Which two configurations should they implement? (Choose two.)
97A company has a Google Cloud organization with several folders and projects. The security team wants to ensure that a specific user cannot create any new projects within the organization, even if they are granted roles that normally allow project creation. What should the team do?
98Your company has a Google Workspace domain and uses Google Cloud. You need to allow a group of contractors to access a specific Cloud Storage bucket. The contractors have Google Accounts but are not in your Workspace domain. You want to grant them access with the least privilege and minimal management overhead. What should you do?
99A company wants to grant a team of developers the ability to manage Compute Engine instances in a specific project. The developers should be able to create, start, stop, and delete instances, but they should not be able to modify IAM policies or access other services. Which predefined role should be granted at the project level?
100A security engineer needs to grant a service account the ability to read objects from a specific Cloud Storage bucket. The service account is used by a Compute Engine instance in the same project. The engineer wants to follow the principle of least privilege and avoid granting permissions to other buckets. What should the engineer do?
101A company uses Google Cloud and wants to ensure that users can only access Compute Engine instances if they have a valid justification and are approved by a manager. They want to implement just-in-time (JIT) access with approval workflows. Which Google Cloud service should they use?
102A company uses Google Cloud Directory Sync (GCDS) to synchronize users from an on-premises LDAP directory to Cloud Identity. They want to ensure that when a user is deleted in the on-premises directory, they immediately lose access to Google Cloud resources. What should they configure?
103A security engineer is configuring IAM conditions to restrict access to a Cloud Storage bucket. The engineer wants to allow users to read objects only if the request originates from a specific VPC network and only during business hours. Which two condition attributes should the engineer use? (Choose two.)
104Your organization uses Google Cloud and wants to enforce that all access to Cloud Storage buckets must come from within the corporate network or from approved devices. You need to implement this using context-aware access. Which two components are required to achieve this? (Choose two.)
105A security engineer is configuring access for a new application running on Compute Engine. The application needs to access a Cloud SQL database and a Cloud Storage bucket. The engineer wants to avoid using service account keys and ensure the application uses the principle of least privilege. What should the engineer do?
106A company has an organization policy that restricts resource locations to 'us-central1' and 'us-east1'. A developer attempts to create a Compute Engine instance in 'europe-west1' using the Compute Engine API and receives a permission denied error. The developer has the roles/compute.instanceAdmin.v1 role at the project level. What is the most likely cause?
107A company uses Google Cloud and has a requirement that all access to their Google Cloud resources must be controlled by their existing third-party identity provider (IdP) using SAML 2.0. They want to ensure that only users who are members of a specific group in the IdP can access Google Cloud, and that these users must use multi-factor authentication (MFA) to sign in. They also want to minimize administrative overhead. Which two steps should the security engineer take to meet these requirements? (Choose two.)
108A security team is using Access Context Manager to define access levels based on IP subnets and device policies. They want to enforce that only users on a corporate network with a trusted device can access a sensitive Cloud Storage bucket via the Google Cloud Console. They have created an access level named 'corp_trusted'. What should they do next to enforce this access level for the bucket?
109A startup has a single Google Cloud project with several Compute Engine instances. They want to grant a new employee the ability to view all resources in the project but not modify anything. Which IAM role should be granted to the employee?
110A security engineer is configuring Identity-Aware Proxy (IAP) to protect an internal web application running on Compute Engine. The engineer wants to grant access to a group of employees. Which two steps are required to allow the employees to access the application through IAP? (Choose two.)
111A company uses Google Cloud and wants to enforce that all external users accessing their web application must be authenticated and authorized via Identity-Aware Proxy (IAP). They need to configure IAP for an external HTTPS load balancer. Which two steps are required to allow access only to members of a specific Google Group? (Choose two.)
112A security engineer is designing an access control strategy for a Google Cloud organization that uses Cloud Identity. The organization wants to ensure that only users who are members of a specific Google Group can access a sensitive project. The engineer plans to use IAM policies and groups. Which two steps should the engineer take to meet this requirement? (Choose two.)
Be able to determine effective access by evaluating IAM allow policies, deny policies, and Organization Policy constraints across the resource hierarchy. The most critical skill is knowing that deny policies override allows, and that constraints like iam.disableServiceAccountKeyCreation prevent key creation regardless of IAM permissions.
The Courseiva PCSE question bank contains 112 questions in the Configuring Access Within a Cloud Solution Environment domain, covering the 25% of the exam attributed to this domain in the official Google Cloud blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Configuring Access Within a Cloud Solution Environment domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included