Google Cloud DevOps Certification 2025 – 400 Free Practice Questions to Pass the Exam

Question: 1 / 400

For accessing monitoring metrics and logs for Compute Engine instances while adhering to least privilege, which roles should be assigned?

Grant the logging.logWriter and monitoring.metricWriter roles to the Compute Engine service accounts.

The selection of granting the logging.logWriter and monitoring.metricWriter roles to the Compute Engine service accounts is appropriate because these roles are designed to adhere to the principle of least privilege while enabling the necessary access to metrics and logs.

The logging.logWriter role allows the service account to write log entries to Cloud Logging, which is essential for tracking operational data and debugging. Meanwhile, the monitoring.metricWriter role enables the service account to write monitoring metrics to Cloud Monitoring. By using these specific roles, you are restricting access to only the permissions needed to perform the respective actions of logging and monitoring, thus minimizing potential security risks associated with broader permissions.

In contrast, options that include roles like logging.admin or monitoring.editor tend to grant more extensive privileges than necessary. The admin role allows for extensive management capabilities, including the ability to delete logs, which goes beyond what is required for standard operation. Similarly, the monitoring.editor role grants broader editing capabilities in Cloud Monitoring that are not needed just to write metrics. These unnecessary permissions can lead to security vulnerabilities, making the least privilege principle not fully respected.

Assigning roles that are too permissive could lead to potential misuse or accidental changes to critical resources, ultimately compromising security and operational integrity. Therefore, the most suitable approach is to assign

Get further explanation with Examzify DeepDiveBeta

Grant the logging.admin and monitoring.editor roles to the Compute Engine service accounts.

Grant the logging.editor and monitoring.metricWriter roles to the Compute Engine service accounts.

Grant the logging.logWriter and monitoring.editor roles to the Compute Engine service accounts.

Next Question

Report this question

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy