Your company's security team has applied the boolean constraint constraints/compute.requireShieldedVm with enforced: TRUE at the Organization level. A development team needs to launch some legacy VM images that are not Shielded-VM-capable in a single project that lives several folders below the Organization node. They add a project-level organization policy for the same constraint and set enforced: FALSE, but deployment of the legacy VMs is still blocked. Which statement best explains this behavior?
Boolean constraints only evaluate the sum of all ancestor policies; because the project set enforced: FALSE, the system should allow non-Shielded VMs, so the issue must be unrelated.
The project's policy failed because enforced: FALSE must be set at the folder level; project-level policies are ignored for boolean constraints.
A lower-level policy cannot override a parent policy that already sets a boolean constraint to enforced; the Organization's setting remains in effect for all descendants.
The project policy was applied correctly, but it takes up to 24 hours for organization-policy changes at lower levels to override parent settings.
For boolean organization policy constraints, inheritance follows a nearest-ancestor wins model only when no ancestor has already enforced the constraint. If any ancestor (Folder or Organization) sets enforced: TRUE, that decision cannot be relaxed by lower-level resources. Because the Organization policy explicitly enforces constraints/compute.requireShieldedVm, the descendant project's attempt to set enforced: FALSE is ignored, and the VMs that are not Shielded cannot be created. To allow exceptions, the security team would need to move the project outside the Organization's scope or remove/modify the Organization-level enforcement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the 'constraints/compute.requireShieldedVm' boolean constraint used for?
Open an interactive chat with Bash
How does the 'nearest-ancestor wins' model work for boolean constraints?
Open an interactive chat with Bash
How can exceptions be made for projects under enforced organization-level constraints?
Open an interactive chat with Bash
What is a boolean constraint in GCP organization policies?
Open an interactive chat with Bash
What does 'nearest-ancestor wins' mean for GCP organization policies?
Open an interactive chat with Bash
How can exceptions be made for organization-level constraints in GCP?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .