Courseiva
Google Cloud Security →easyMultiple Choice

Cloud Digital Leader Google Cloud Security Practice Question

Which IAM component determines what actions a user is allowed to perform on a resource?

⚠ Common exam trap

The trap is the authentication-versus-authorization distinction; candidates who see 'allowed to perform' may pick authentication because both concepts are about access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorization

Authorization is the IAM component that determines what an authenticated principal is allowed to do on a resource; it evaluates policies attached to users, groups, roles, and resources to allow or deny specific actions. Authentication establishes identity, while authorization decides permissions — so authorization is the correct answer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Authorization

    Why this is correct

    Authorization is the IAM component that explicitly determines which actions a user is permitted to perform on a given set of resources. In Google Cloud, this is implemented by binding principals to roles, each containing a collection of permissions, and attaching those bindings to projects, folders, or organizations. The authorization engine evaluates the requested action against the effective allow policies and renders a definitive allow or deny decision.

  • ✗

    Audit Logging

    Why it's wrong here

    Audit Logging records a chronological trail of who performed which action on what resource, but it does not influence whether that action is permitted. It is a detective control that supports security forensics, compliance, and monitoring, yet it plays no role in the authorization decision. The IAM component that governs allowed actions is separate from the logging subsystem that documents the consequences of those decisions.

  • ✗

    Authentication

    Why it's wrong here

    Authentication verifies the identity of a principal by validating credentials such as passwords, OAuth tokens, or service account keys. While this step confirms that you are who you claim to be, it never defines what operations you are allowed to perform. Authorization is a subsequent, distinct phase that maps the authenticated identity to specific permissions via IAM policies, so authentication alone cannot answer the question of allowed actions.

  • ✗

    Encryption

    Why it's wrong here

    Encryption protects data confidentiality by converting readable plaintext into ciphertext that cannot be interpreted without the correct cryptographic key. Although it is essential for securing data at rest and in transit, encryption does not govern which actions a user is allowed to execute; it is a confidentiality control, not an access-control mechanism. IAM authorization determines access, whereas encryption ensures that even if unauthorized access occurs, the data remains unintelligible.

About these practice questions

This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.