Your company has a Cloud Identity organization with several folders that map to environments. The security team wants to guarantee that no new Compute Engine VM in any future project can receive a public (external) IPv4 address, except for projects that reside in the existing "dev" folder. As the associate cloud engineer, which configuration will meet this requirement with the least ongoing administration effort?
Apply the Organization Policy constraint constraints/compute.vmExternalIpAccess with a DENY rule at the Organization node and add an ALLOW policy on the dev folder.
Place all non-dev projects in a VPC Service Controls perimeter that disallows external network egress.
Create a default-network firewall rule at the Organization level that blocks all egress traffic and remove it from the dev folder.
Remove the compute.instances.create permission from the Compute Engine default service account for every project except those under the dev folder.
The VM external IP restriction is best enforced with an Organization Policy constraint. Setting the constraint constraints/compute.vmExternalIpAccess to DENY at the Organization level blocks assignment of external IPv4 addresses for all new VMs in descendant resources. Because Organization Policy settings are inherited, adding an ALLOW policy for the same constraint on the dev folder overrides the inherited deny, permitting public IPs only in that folder. Firewall rules or VPC-SC perimeters do not stop the allocation of external IPs, and altering IAM permissions would affect many unrelated Compute Engine operations.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is `constraints/compute.vmExternalIpAccess` in GCP?
Open an interactive chat with Bash
What is an Organization Policy in GCP?
Open an interactive chat with Bash
Why are firewall rules insufficient for blocking external IP addresses?
Open an interactive chat with Bash
What is an Organization Policy constraint in GCP?
Open an interactive chat with Bash
How does inheritance work for GCP Organization Policies?
Open an interactive chat with Bash
What does the constraint `constraints/compute.vmExternalIpAccess` do?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .