🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 59 minutes remaining!

GCP Associate Cloud Engineer Practice Question

Your company has a Google Cloud organization with separate folders for "prod" and "dev" projects. Security mandates that no new Compute Engine VM in any project under the prod folder may receive an external IPv4 address, but development teams must remain free to create such VMs in their own folder. Which approach best meets these requirements with the least administrative overhead?

  • Delete the default VPC network in each prod project and require teams to create only custom subnets without any organization policy.

  • Apply the constraint constraints/compute.vmCanIpForward in Deny mode on the organization node to block external IPs for every VM.

  • Remove the roles/compute.networkUser IAM role from all service accounts in prod projects to prevent them from getting external IP addresses.

  • Apply the organization policy constraint constraints/compute.vmExternalIpAccess in Deny mode on the prod folder so it is inherited by all production projects.

GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot