mediumMultiple Choice
Google ACE Practice Question: Your team needs to manage Google Kubernetes…
Your team needs to manage Google Kubernetes Engine clusters across multiple projects. Rather than granting `roles/container.admin` on each project individually, you want a centralized approach. What is the most maintainable solution?
⚠ Common exam trap
Test-takers frequently confuse Kubernetes RBAC (which controls access within a cluster) with Google Cloud IAM (which controls access to the GKE API and cluster management), leading them to choose fleet-based RBAC solutions that do not address the centralized IAM requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant `roles/container.admin` to the team's Google Group at the folder level containing all relevant projects.
Granting `roles/container.admin` at the folder level to a Google Group is the most maintainable solution because it centralizes IAM policy management. When new projects are added under that folder, they automatically inherit the role, and team membership changes are handled by updating the Google Group rather than modifying individual project IAM policies. This approach follows Google Cloud's recommended practice of using groups and resource hierarchy for scalable access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a service account with `roles/container.admin` and share its key JSON with team members.
Why it's wrong here
A shared service-account key is a long-lived credential that cannot be attributed to individual users and must be rotated manually, so it fails the centralised, maintainable requirement. It is tempting because service accounts suit automated workloads, but human team access should use federated identities or groups instead.
- ✓
Grant `roles/container.admin` to the team's Google Group at the folder level containing all relevant projects.
Why this is correct
Granting `roles/container.admin` to a Google Group at the folder level lets every current and future project beneath that folder inherit the role, satisfying the centralised, maintainable requirement. Adding or removing members changes access everywhere at once, avoiding per-project IAM bindings.
- ✗
Grant `roles/container.admin` to each team member individually in each project's IAM policy.
Why it's wrong here
Per-project, per-member grants must be repeated and audited in every project's IAM policy, which is exactly the maintenance burden the scenario asks to remove. It is tempting because direct IAM bindings are simple for a single project, but centralisation requires granting at the organisation or folder level.
- ✗
Use the GKE Hub to create a fleet and assign RBAC roles within each cluster.
Why it's wrong here
GKE Hub fleets provide multi-cluster configuration and policy propagation, not IAM authorisation for the container.admin role on projects. It is tempting because fleets centralise cluster management, but they do not grant project-level IAM permissions, which must come from organisation or folder-level role bindings.
Go deeper
Related to this question
Learn chapter
Google Compute Engine
Key term
IAM
Identity and Access Management (IAM) is a framework of policies and technologies that ensures the right individuals have the appropriate access to technology resources.
Key term
Folder
A folder is a logical container used to organize and group digital files, resources, or cloud-based assets within a system or platform.
About these practice questions
Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.