Your company's security team wants to guarantee that, by default, no new Compute Engine VM instances in any project can obtain an external IPv4 address. However, they also want the flexibility to grant an exception later for a specific project used by the penetration-testing team. Which Google Cloud feature best satisfies these requirements and what action should you take first?
Grant only the Compute Engine internal access IAM role to project owners and rely on VPC Service Controls to block public endpoints.
Create an Organization Policy at the Organization node that sets the constraint constraints/compute.vmExternalIpAccess to Deny.
Apply a VPC firewall rule at the Organization level that blocks all egress traffic from external IP addresses.
Attach a Cloud Armor security policy to every project's default network that denies traffic from 0.0.0.0/0.
An Organization Policy provides centralized, hierarchy-aware controls over resources. Setting the constraint constraints/compute.vmExternalIpAccess to Deny at the Organization node blocks the creation of VMs with external IP addresses in every folder and project that inherits the policy. Because policies are inherited downward but can be overridden lower in the tree, the security team can later create a less restrictive policy on the penetration-testing project to permit external addresses. VPC firewall rules, IAM roles, Cloud Armor, or VPC Service Controls cannot universally prevent the assignment of external IPs across all projects; they operate at different layers or scopes and do not enforce this configuration setting during VM creation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Organization Policy in Google Cloud?
Open an interactive chat with Bash
How does the constraint `constraints/compute.vmExternalIpAccess` work?
Open an interactive chat with Bash
Why are VPC firewall rules not effective for this scenario?
Open an interactive chat with Bash
What is an Organization Policy in Google Cloud?
Open an interactive chat with Bash
What does the constraint `constraints/compute.vmExternalIpAccess` do?
Open an interactive chat with Bash
Why don’t VPC firewall rules, IAM roles, Cloud Armor, or VPC Service Controls work for this use case?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .