Valid Professional-Cloud-Security-Engineer Dumps shared by EduDump.com for Helping Passing Professional-Cloud-Security-Engineer Exam! EduDump.com now offer the newest Professional-Cloud-Security-Engineer exam dumps, the EduDump.com Professional-Cloud-Security-Engineer exam questions have been updated and answers have been corrected get the newest EduDump.com Professional-Cloud-Security-Engineer dumps with Test Engine here:
Your organization uses the top-tier folder to separate application environments (prod and dev). The developers need to see all application development audit logs but they are not permitted to review production logs. Your security team can review all logs in production and development environments. You must grant Identity and Access Management (1AM) roles at the right resource level tor the developers and security team while you ensure least privilege. What should you do?
Correct Answer: C
To ensure that the developers can view audit logs for the development environment and the security team can review all logs, you should grant IAM roles at the appropriate resource levels: Grant logging.admin Role to the Security Team: Assign the logging.admin role to the security team at the organization resource level. This grants the security team full access to all logging data across the organization, including both production and development environments. Grant logging.viewer Role to the Developer Team: Assign the logging.viewer role to the developer team at the folder resource level that contains all the development projects. This restricts the developers' access to only view logs in the development environment, ensuring they do not have access to production logs. By using these roles and assigning them at the appropriate levels, you ensure that each team has the access they need while adhering to the principle of least privilege. IAM Roles for Cloud Logging Resource Hierarchy in Google Cloud