Your company has an Organization node in Google Cloud. You must isolate production and development workloads for each department, allowing administrators to apply department-specific IAM roles and organization policy constraints while still inheriting company-wide controls. Which resource-hierarchy design meets these goals with the least repeated configuration?
Keep all projects directly under the Organization node, apply identifying labels for department and environment, and manage IAM roles and policy constraints individually on each project.
Create a folder for each department under the Organization node and, inside each department folder, create child folders named production and development; place projects in the appropriate child folder and set IAM and policies at the folder levels.
Create one top-level folder called environments with two child folders, production and development, and place every department's projects into the shared environment folders.
Register a separate Cloud Identity tenant for every department to obtain multiple Organization nodes, then create projects directly under each organization.
Using a folder for every department and nesting environment-specific subfolders lets you attach IAM roles and organization policy constraints once per department and once per environment. Those settings are inherited by all projects placed inside, while company-wide controls applied at the Organization node continue to flow downward. Labels cannot carry IAM or policy inheritance, separate Organization nodes add unnecessary administrative overhead, and using environment folders shared by all departments does not prevent one department's administrators from affecting another department's projects.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of an Organization node in GCP?
Open an interactive chat with Bash
How does IAM inheritance work in a GCP resource hierarchy?
Open an interactive chat with Bash
Why are folders useful in organizing resources in GCP?
Open an interactive chat with Bash
What is a Google Cloud Organization node?
Open an interactive chat with Bash
How do IAM roles work in Google Cloud resource hierarchy?
Open an interactive chat with Bash
What are organization policy constraints in Google Cloud?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .