Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 179 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 179

Single answerGoogle Cloud Platform

Your organization requires that no external IP addresses are assigned to virtual machines (VMs) across all projects to minimize the attack surface. You need to implement a solution using Google Cloud's organization policies to enforce this requirement. What is the best approach to achieve this?

  1. A

    Set the 'constraints/compute.vmExternalIpAccess' constraint at the organization level and enforce it.

  2. B

    Assign a custom IAM role to all projects that disallows creating VMs with external IP addresses.

  3. C

    Manually monitor and remove any VMs with external IP addresses from all projects.

  4. D

    Enable the 'constraints/compute.vmExternalIpAccess' constraint only at the folder level for specific departments.

Show answer and explanation

Correct answer: A

Explanation

To enforce the restriction of external IPs on VMs across all projects, the 'constraints/compute.vmExternalIpAccess' constraint should be set at the organization level. This approach ensures that the policy is uniformly applied and prevents the creation of VMs with external IPs organization-wide.

  • A. Correct.

    This is the correct approach. The 'constraints/compute.vmExternalIpAccess' organization policy constraint can be used to restrict external IPs for VMs and can be enforced at the organization level to apply to all projects.

  • B. Incorrect.

    IAM roles control permissions but do not enforce resource configurations. This approach is not suitable for restricting external IPs on VMs.

  • C. Incorrect.

    Manual monitoring is inefficient, error-prone, and does not provide a scalable or enforceable solution for restricting external IPs.

  • D. Incorrect.

    While enabling the constraint at the folder level is possible, it does not fulfill the requirement of applying this restriction across all projects in the organization.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam