🔥 40% Off Crucial Exams Memberships — Deal ends today!

20 minutes, 9 seconds remaining!

GCP Associate Cloud Engineer Practice Question

Your company's Google Cloud Organization has two top-level folders: Prod and Dev. Security policy states that, by default, new Compute Engine VM instances must not receive external IPv4 addresses, but developers working in the Dev folder occasionally need to create test instances with public IPs. What is the most efficient way to satisfy these requirements while minimizing ongoing administration?

  • Individually set the constraints/compute.vmExternalIpAccess policy to DENY on each Prod project and leave it unset on Dev projects.

  • Apply the constraints/compute.vmExternalIpAccess organization policy with a DENY rule at the Organization node, and add an ALLOW policy override on the Dev folder.

  • Disable the Compute Engine API in all Prod projects and enable it only in Dev projects when external IPs are required.

  • Create a VPC firewall rule in every Prod project that blocks egress to 0.0.0.0/0 while leaving Dev projects unchanged.

GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot