Cloud Digital Leader Google Cloud Security Practice Question
Which IAM component determines what actions a user is allowed to perform on a resource?
⚠ Common exam trap
The trap is the authentication-versus-authorization distinction; candidates who see 'allowed to perform' may pick authentication because both concepts are about access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorization
Authorization is the IAM component that determines what an authenticated principal is allowed to do on a resource; it evaluates policies attached to users, groups, roles, and resources to allow or deny specific actions. Authentication establishes identity, while authorization decides permissions — so authorization is the correct answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authorization
Why this is correct
Authorization is the IAM component that explicitly determines which actions a user is permitted to perform on a given set of resources. In Google Cloud, this is implemented by binding principals to roles, each containing a collection of permissions, and attaching those bindings to projects, folders, or organizations. The authorization engine evaluates the requested action against the effective allow policies and renders a definitive allow or deny decision.
- ✗
Audit Logging
Why it's wrong here
Audit Logging records a chronological trail of who performed which action on what resource, but it does not influence whether that action is permitted. It is a detective control that supports security forensics, compliance, and monitoring, yet it plays no role in the authorization decision. The IAM component that governs allowed actions is separate from the logging subsystem that documents the consequences of those decisions.
- ✗
Authentication
Why it's wrong here
Authentication verifies the identity of a principal by validating credentials such as passwords, OAuth tokens, or service account keys. While this step confirms that you are who you claim to be, it never defines what operations you are allowed to perform. Authorization is a subsequent, distinct phase that maps the authenticated identity to specific permissions via IAM policies, so authentication alone cannot answer the question of allowed actions.
- ✗
Encryption
Why it's wrong here
Encryption protects data confidentiality by converting readable plaintext into ciphertext that cannot be interpreted without the correct cryptographic key. Although it is essential for securing data at rest and in transit, encryption does not govern which actions a user is allowed to execute; it is a confidentiality control, not an access-control mechanism. IAM authorization determines access, whereas encryption ensures that even if unauthorized access occurs, the data remains unintelligible.
Go deeper
Related to this question
Learn chapter
IAM Concepts: Principals, Roles, and Bindings
Key term
IAM
Identity and Access Management (IAM) is a framework of policies and technologies that ensures the right individuals have the appropriate access to technology resources.
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
About these practice questions
This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.