Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 173 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 173

Single answerGoogle Cloud Platform

Your organization is managing hundreds of Google Cloud projects across multiple teams. To ensure consistent security policies, you need to set up a folder hierarchy that enforces IAM roles and organization policies across different teams while allowing team-specific project-level configuration. What is the best approach to achieve this?

  1. A

    Create a single folder for all teams and apply IAM roles and organization policies at the folder level.

  2. B

    Create separate folders for each team under the organization node and apply IAM roles and organization policies at the respective folder level.

  3. C

    Manage all projects directly under the organization node and apply IAM roles and organization policies at the organization level.

  4. D

    Use labels on projects to group them by teams and set IAM roles and organization policies using these labels.

Show answer and explanation

Correct answer: B

Explanation

The best practice for managing projects at scale is to create a structured folder hierarchy under the organization node. Assigning separate folders for each team allows you to enforce consistent security policies via IAM roles or organization policies at the folder level while still enabling flexibility for team-specific configurations at the project level. This ensures scalability, maintainability, and better control over resource access.

  • A. Incorrect.

    This approach does not allow for team-specific configurations since all projects are under the same folder, making it harder to manage granular policies.

  • B. Correct.

    Creating separate folders for each team under the organization node allows you to enforce consistent policies at the folder level while still enabling team-specific configurations for projects within their respective folders.

  • C. Incorrect.

    Managing all projects directly under the organization node makes it difficult to enforce granular team-specific policies, as all projects would inherit the same policies from the organization level.

  • D. Incorrect.

    Labels are useful for organizing and filtering projects but cannot be used to enforce IAM roles or organization policies, as those must be applied at the resource hierarchy level (organization, folder, or project).

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam