Courseiva

Google ACE Configuring Access and Security Practice Question

A company is using Cloud Identity and wants to grant a group of auditors read-only access to all resources in a project, but they must not be able to modify any IAM policies. Which two roles should be granted to the group? (Choose two.)

⚠ Common exam trap

The trap here is assuming that roles with 'viewer' or 'reviewer' in the name might include write permissions, or that broader roles like Editor are needed for comprehensive access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

roles/viewer

The Viewer role provides read-only access to resources, while the Security Reviewer role allows viewing IAM policies without modification. Together, they enable auditors to inspect all resources and access controls without the ability to make changes. This combination adheres to the principle of least privilege and meets the requirement of read-only access with no IAM policy modifications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    roles/editor

    Why it's wrong here

    The Editor role grants broad modify permissions across most services, including the ability to change resources. It violates the requirement of read-only access and could allow auditors to alter configurations. Additionally, Editor does not include permission to modify IAM policies, but it still provides excessive write access that is not suitable for auditors.

  • ✓

    roles/viewer

    Why this is correct

    The Viewer role provides read-only access to all resources within a project, excluding sensitive data and IAM policies. It allows auditors to view resources without the ability to modify them. This role is appropriate for granting broad read access while preventing changes, and it does not include permissions to alter IAM policies.

  • ✗

    roles/iam.organizationRoleAdmin

    Why it's wrong here

    This role allows managing organization-level IAM roles, including creating and modifying custom roles. It is far too permissive and grants write access to IAM configurations. Auditors should not have the ability to change roles or policies. This role does not meet the read-only requirement and would give unnecessary administrative capabilities.

  • ✗

    roles/resourcemanager.projectIamAdmin

    Why it's wrong here

    This role grants full control over IAM policies at the project level, including the ability to grant and revoke access. It directly violates the requirement that auditors must not be able to modify any IAM policies. Even though it is focused on IAM, it provides write access, which is not appropriate for a read-only auditor role.

  • ✓

    roles/iam.securityReviewer

    Why this is correct

    The Security Reviewer role grants permissions to view IAM policies and other security-related configurations, but not to modify them. It is designed for auditors who need to review access controls. Combining this with the Viewer role gives read-only access to resources and the ability to inspect IAM policies without granting any write permissions.

About these practice questions

Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.