Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 590 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 590

Single answerGoogle Cloud Platform

You are a Cloud Network Engineer at an organization that heavily manages its network resources with Google Cloud. The security team has requested that Cloud NAT should only be created in specific projects to ensure compliance with internal security policies. How can you enforce this restriction across the organization?

  1. A

    Create an organization policy with the 'compute.restrictCloudNATUsage' constraint and configure it to allow only the required projects.

  2. B

    Enable the 'compute.restrictCloudNATUsage' constraint at the folder level and set it to deny all projects except the required ones.

  3. C

    Set up a VPC Service Control perimeter and include only the required projects to restrict Cloud NAT usage.

  4. D

    Apply an IAM policy to deny the 'roles/compute.networkAdmin' role for all projects except the required ones.

Show answer and explanation

Correct answer: A

Explanation

To enforce restrictions on Cloud NAT creation across an organization, you should use the 'compute.restrictCloudNATUsage' organization policy constraint. This approach ensures that only specific projects can create Cloud NAT resources while maintaining compliance with organizational policies. Other options, such as IAM or VPC Service Controls, do not directly address the requirement to restrict Cloud NAT creation.

  • A. Correct.

    This is correct. The 'compute.restrictCloudNATUsage' organization policy constraint allows administrators to enforce restrictions on Cloud NAT creation at the organization or folder level. By setting this constraint and specifying the allowed projects, you can ensure compliance.

  • B. Incorrect.

    This is incorrect. While folder-level constraints are possible, the question specifies enforcing the restriction across the organization, which requires setting the policy at the organization level.

  • C. Incorrect.

    This is incorrect. VPC Service Controls are used for protecting data exfiltration and do not directly restrict the creation or use of Cloud NAT.

  • D. Incorrect.

    This is incorrect. IAM policies control permissions for users and service accounts but do not enforce resource creation restrictions like Cloud NAT usage.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam