Cloud Digital Leader Google Cloud Security Practice Question
A large enterprise wants to enforce the principle of least privilege for its cloud resources. The security team needs to audit all IAM policy changes across the organization and ensure that custom roles are used where predefined roles are too permissive. Which three Google Cloud services or features should be combined to achieve this? (Choose three.)
⚠ Common exam trap
GCDL often tests the confusion between Security Command Center (posture/findings) and Cloud Audit Logs (the actual audit source) — candidates pick SCC for 'audit' questions when the precise answer is Audit Logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IAM Recommender
IAM Recommender (A) is correct because it analyzes actual resource usage and generates least-privilege recommendations, such as suggesting replacements for overly broad predefined roles with narrower custom roles. Cloud Audit Logs (C) is correct because Admin Activity audit logs record all IAM policy changes (SetIamPolicy calls) across the organization, providing the audit trail the security team requires. Organization Policies (D) is correct because constraints like iam.allowedPolicyMemberDomains and iam.disableServiceAccountKeyCreation enforce guardrails at the org/folder/project level, helping restrict permissions and enforce least privilege consistently. Cloud Key Management Service (B) is wrong because it manages encryption keys, not IAM policy auditing or role scoping. Security Command Center (E) is wrong because it focuses on security posture, threat detection, and vulnerability findings rather than auditing IAM policy changes or recommending custom roles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IAM Recommender
Why this is correct
IAM Recommender leverages Google Cloud's usage data and machine learning to analyze each principal's actual permissions usage over the past 90 days, then generates role recommendations that remove unnecessary permissions and flags over-privileged accounts. It surfaces findings like role churn or unused roles, and supports applying the suggested least-privilege bindings directly or via Terraform, enabling continuous, data-driven remediation of excessive IAM permissions without disrupting existing workflows.
- ✗
Cloud Key Management Service
Why it's wrong here
Cloud Key Management Service (Cloud KMS) is fundamentally a cryptographic key management system that lets you create, import, rotate, and destroy symmetric and asymmetric encryption keys used to protect data at rest and in transit. It does not analyze IAM policies, recommend role adjustments, or enforce least-privilege access; instead, it provides key material and operations on that material, with IAM often used to control access to the keys themselves, not to assess or optimize user roles across the organization.
- ✓
Cloud Audit Logs
Why this is correct
Cloud Audit Logs records each IAM policy change as an Admin Activity audit log entry, capturing who made the change, what change was made, and when it occurred, which is essential for compliance, forensic analysis, and post-incident review. However, these logs are a passive record of historical events; they do not analyze existing roles for over-privilege, generate least-privilege recommendations, or actively suggest role modifications, so they support auditing governance but not proactive IAM optimization.
- ✓
Organization Policies
Why this is correct
Organization Policies allow you to set constraints on Cloud Resource Manager nodes, for example using the `iam.automaticIamGrantsForDefaultServiceAccounts` constraint or custom constraints to restrict role assignments, such as requiring that only custom roles with precisely defined permissions are used instead of broader predefined roles. While this can indirectly enforce least privilege by limiting what is available, it does not inspect current usage or recommend specific role adjustments; it is a guardrail that prevents certain configurations rather than an analyzer that identifies and suggests least-privilege roles for existing principals.
- ✗
Security Command Center
Why it's wrong here
Security Command Center (SCC) is a security and risk management platform that aggregates findings from services like Web Security Scanner and Cloud Armor, detects vulnerabilities such as open firewall ports or misconfigured network settings, and provides threat detection through Event Threat Detection and Continuous Monitoring with Security Health Analytics. Although SCC includes IAM-related findings like 'Role was granted to a user' or 'Policy in violation', it does not perform usage-based IAM role optimization, nor does it recommend specific least-privilege roles; its focus is on discovering active threats and compliance issues, not on proactive IAM policy refinement based on permission usage.
Go deeper
Related to this question
Learn chapter
Google Cloud Next Features and Announcements
Key term
Google Cloud
Google Cloud is a suite of cloud computing services offered by Google that provides infrastructure, platform, and software solutions over the internet.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.