Courseiva
mediumMultiple Choice

Google ACE Practice Question: Your team needs to manage Google Kubernetes…

Your team needs to manage Google Kubernetes Engine clusters across multiple projects. Rather than granting `roles/container.admin` on each project individually, you want a centralized approach. What is the most maintainable solution?

⚠ Common exam trap

Test-takers frequently confuse Kubernetes RBAC (which controls access within a cluster) with Google Cloud IAM (which controls access to the GKE API and cluster management), leading them to choose fleet-based RBAC solutions that do not address the centralized IAM requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant `roles/container.admin` to the team's Google Group at the folder level containing all relevant projects.

Granting `roles/container.admin` at the folder level to a Google Group is the most maintainable solution because it centralizes IAM policy management. When new projects are added under that folder, they automatically inherit the role, and team membership changes are handled by updating the Google Group rather than modifying individual project IAM policies. This approach follows Google Cloud's recommended practice of using groups and resource hierarchy for scalable access control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a service account with `roles/container.admin` and share its key JSON with team members.

    Why it's wrong here

    A shared service-account key is a long-lived credential that cannot be attributed to individual users and must be rotated manually, so it fails the centralised, maintainable requirement. It is tempting because service accounts suit automated workloads, but human team access should use federated identities or groups instead.

  • ✓

    Grant `roles/container.admin` to the team's Google Group at the folder level containing all relevant projects.

    Why this is correct

    Granting `roles/container.admin` to a Google Group at the folder level lets every current and future project beneath that folder inherit the role, satisfying the centralised, maintainable requirement. Adding or removing members changes access everywhere at once, avoiding per-project IAM bindings.

  • ✗

    Grant `roles/container.admin` to each team member individually in each project's IAM policy.

    Why it's wrong here

    Per-project, per-member grants must be repeated and audited in every project's IAM policy, which is exactly the maintenance burden the scenario asks to remove. It is tempting because direct IAM bindings are simple for a single project, but centralisation requires granting at the organisation or folder level.

  • ✗

    Use the GKE Hub to create a fleet and assign RBAC roles within each cluster.

    Why it's wrong here

    GKE Hub fleets provide multi-cluster configuration and policy propagation, not IAM authorisation for the container.admin role on projects. It is tempting because fleets centralise cluster management, but they do not grant project-level IAM permissions, which must come from organisation or folder-level role bindings.

About these practice questions

Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.