GCP Professional Cloud Architect Practice Question
Your company has a single Google Cloud organization. Security requires strict separation of production and development resources. A small central security team must enforce IAM roles and Organization Policy constraints-such as blocking external VM IPs-across every production resource without touching each project, while product teams keep full IAM control within their own projects. As more teams join the platform, which Google Cloud resource-hierarchy design best meets these needs and keeps operational overhead low?
Tag every project with an environment label (prod or dev) and rely on label-based log sinks so the security team can detect and remediate non-compliant production resources.
Create two top-level folders (Prod and NonProd) under the organization. Give each product team its own folder or projects beneath the appropriate environment folder, and apply security team IAM roles and Organization Policy constraints at the Prod folder.
Keep all projects in a single folder and have the security team add IAM Conditions to each project's policy to distinguish production from development access.
Create a separate Google Cloud organization for production and migrate all production projects there while leaving development projects in the current organization.
Placing all production projects under a dedicated top-level Production folder and all non-production projects under another folder cleanly separates the two environments. Because IAM policies and Organization Policy constraints inherit to child folders and projects, the security team can attach restrictive constraints and grant itself administrative IAM roles once at the Production folder and automatically cover every descendant project, present or future. Product teams retain autonomy inside their own child folders or projects. Creating separate organizations removes shared billing and visibility, labels cannot enforce policies, and managing IAM conditions per project does not scale.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does Google Cloud's folder hierarchy help enforce security policies?
Open an interactive chat with Bash
What is an Organization Policy constraint in Google Cloud?
Open an interactive chat with Bash
Why is using separate top-level folders better than creating multiple organizations?
Open an interactive chat with Bash
What is the Google Cloud resource hierarchy?
Open an interactive chat with Bash
How do IAM roles interact with resource hierarchy levels?
Open an interactive chat with Bash
What are Organization Policy constraints in Google Cloud?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .