Courseiva

Google ACE Configuring Access and Security Practice Question

An engineer needs to grant an external auditor read-only access to view IAM policies on a GCP project. The auditor should not have access to any other resources. Which IAM role should be assigned?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

roles/iam.securityReviewer

The `roles/iam.securityReviewer` role grants permission to view IAM policies without granting access to other resources. It is specifically designed for security auditors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    roles/iam.roleAdmin

    Why it's wrong here

    roles/iam.roleAdmin grants permissions to create, update, and delete custom roles, and to perform other role administration tasks across the project. Since the auditor only needs to view IAM policies, this role introduces the risk of role changes and privilege escalation, far exceeding read-only requirements. It is therefore inappropriate.

  • ✗

    roles/iam.serviceAccountAdmin

    Why it's wrong here

    roles/iam.serviceAccountAdmin allows managing service accounts, including rotating keys, deleting accounts, and changing permissions on service accounts. These abilities are unrelated to inspecting IAM policies and could damage resources if misused. An auditor does not need any service account management capabilities, so this role violates least privilege.

  • ✗

    roles/viewer

    Why it's wrong here

    roles/viewer provides read-only access to every resource in the project, including compute instances, storage buckets, and networking configurations, not just IAM policies. While it does allow viewing IAM bindings, the auditor's task is specifically to review access policies, so the broad scope exposes potentially sensitive configuration data beyond the audit requirement. The principle of least privilege dictates using a narrower role.

  • ✓

    roles/iam.securityReviewer

    Why this is correct

    roles/iam.securityReviewer is the correct choice because it grants permission to view IAM policies (for example, 'getIamPolicy') across all resources without allowing any modifications. It also includes permissions to list and get roles, which is exactly what an external auditor needs to review access configuration. This role aligns with least privilege for a read-only audit.

About these practice questions

Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.