Google ACE Configuring Access and Security Practice Question
A company is using Cloud Identity and wants to grant a group of auditors read-only access to all resources in a project, but they must not be able to modify any IAM policies. Which two roles should be granted to the group? (Choose two.)
⚠ Common exam trap
The trap here is assuming that roles with 'viewer' or 'reviewer' in the name might include write permissions, or that broader roles like Editor are needed for comprehensive access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
roles/viewer
The Viewer role provides read-only access to resources, while the Security Reviewer role allows viewing IAM policies without modification. Together, they enable auditors to inspect all resources and access controls without the ability to make changes. This combination adheres to the principle of least privilege and meets the requirement of read-only access with no IAM policy modifications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
roles/editor
Why it's wrong here
The Editor role grants broad modify permissions across most services, including the ability to change resources. It violates the requirement of read-only access and could allow auditors to alter configurations. Additionally, Editor does not include permission to modify IAM policies, but it still provides excessive write access that is not suitable for auditors.
- ✓
roles/viewer
Why this is correct
The Viewer role provides read-only access to all resources within a project, excluding sensitive data and IAM policies. It allows auditors to view resources without the ability to modify them. This role is appropriate for granting broad read access while preventing changes, and it does not include permissions to alter IAM policies.
- ✗
roles/iam.organizationRoleAdmin
Why it's wrong here
This role allows managing organization-level IAM roles, including creating and modifying custom roles. It is far too permissive and grants write access to IAM configurations. Auditors should not have the ability to change roles or policies. This role does not meet the read-only requirement and would give unnecessary administrative capabilities.
- ✗
roles/resourcemanager.projectIamAdmin
Why it's wrong here
This role grants full control over IAM policies at the project level, including the ability to grant and revoke access. It directly violates the requirement that auditors must not be able to modify any IAM policies. Even though it is focused on IAM, it provides write access, which is not appropriate for a read-only auditor role.
- ✓
roles/iam.securityReviewer
Why this is correct
The Security Reviewer role grants permissions to view IAM policies and other security-related configurations, but not to modify them. It is designed for auditors who need to review access controls. Combining this with the Viewer role gives read-only access to resources and the ability to inspect IAM policies without granting any write permissions.
Go deeper
Related to this question
Learn chapter
Cloud Storage Bucket Security
Key term
IAM policy
An IAM policy is a set of rules that determines who can access specific cloud resources and what actions they are allowed to perform.
Key term
IAM
Identity and Access Management (IAM) is a framework of policies and technologies that ensures the right individuals have the appropriate access to technology resources.
About these practice questions
Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.