🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 58 minutes remaining!

GCP Associate Cloud Engineer Practice Question

You are the organization administrator for ExampleCorp's Google Cloud environment. Security mandates that no new Compute Engine VM in any project should obtain an external IPv4 address, except for the network-engineering team that works only in the vpc-test project. Which configuration best meets this requirement while preserving least-privilege and minimizing repetitive work?

  • Create an IAM Deny policy at the Organization level that blocks the compute.instances.create permission for all users, then add an allow rule in the vpc-test project.

  • Grant the network-engineering team the Compute Instance Admin role in the vpc-test project and remove that role from all other projects.

  • Delete the default VPC network from every project and create custom VPCs without Internet gateways; leave the default network intact in the vpc-test project.

  • Apply the compute.vmExternalIpAccess constraint at the Organization level with "enforce" set to true (deny all), then add a project-level policy on vpc-test that allows only the network-engineering service account to use external IP addresses.

GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot