Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 177 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 177

Single answerGoogle Cloud Platform

Your organization has a policy requiring that no external IP addresses are assigned to virtual machines (VMs) in production projects. You want to enforce this policy across all production projects in the organization. How should you achieve this?

  1. A

    Apply the 'constraints/compute.vmExternalIpAccess' constraint at the organization level with the condition to target only production projects.

  2. B

    Apply the 'constraints/compute.vmExternalIpAccess' constraint at the folder level containing the production projects.

  3. C

    Create a custom organization policy that denies external IP addresses and apply it to each production project individually.

  4. D

    Apply the 'constraints/compute.vmExternalIpAccess' constraint at the project level for each production project.

Show answer and explanation

Correct answer: A

Explanation

The 'constraints/compute.vmExternalIpAccess' constraint is a pre-built organization policy that can be used to restrict external IP access for VMs. Applying it at the organization level with a condition targeting production projects ensures that the policy is enforced consistently and automatically across all applicable projects. This approach is more scalable and efficient than applying the constraint at the folder or project level or creating custom policies for each project.

  • A. Correct.

    This is correct. Applying the 'constraints/compute.vmExternalIpAccess' constraint at the organization level with a condition targeting production projects ensures centralized policy enforcement without manual application to each project.

  • B. Incorrect.

    This is incorrect. Applying the constraint at the folder level may work if all production projects are in a single folder, but it lacks flexibility for projects outside the folder and is less comprehensive than applying it at the organization level.

  • C. Incorrect.

    This is incorrect. Creating custom organization policies for each project is time-consuming, error-prone, and not a recommended practice when a pre-built constraint like 'constraints/compute.vmExternalIpAccess' is available.

  • D. Incorrect.

    This is incorrect. Applying the constraint at the project level for each production project requires manual effort and is not scalable or efficient for managing multiple projects.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam