GCP Professional Cloud Architect Practice Question

Your company's Google Cloud organization (orgA) is acquiring startup orgB. About 30 production projects must move from orgB into orgA. Requirements: 1) orgB engineers keep Project Owner rights on their migrated projects; 2) the enterprise security team must enforce a ban on external IPv4 addresses for all production projects, without affecting development projects; 3) only the Cloud Foundation team may move projects and folders; 4) development-specific IAM bindings must not propagate to production. Which design meets all requirements with minimal ongoing administration?

  • Create a single Migrated-Projects folder under orgA, move all orgB projects there, enforce the external-IP ban with shared-VPC firewall rules, inherit Development folder IAM to the new folder, and grant orgB engineers project-level owner via a folder-level binding.

  • Place all migrated projects directly under orgA. Apply compute.vmExternalIpAccess=DENY at the organization root, grant the Cloud Foundation team the Owner role on orgA to move projects, and leave Development folder IAM unchanged.

  • Create sibling folders named Production and Development under orgA. Grant the Cloud Foundation team roles/resourcemanager.projectMover on orgA. Move all orgB production projects into the Production folder. Apply the compute.vmExternalIpAccess=DENY constraint at the Production folder. Re-grant orgB engineers roles/resourcemanager.projectOwner on each migrated project.

  • Keep orgB as a subfolder inside a new Production folder. Apply the external-IP deny policy individually to every project. Give Cloud Foundation roles/resourcemanager.folderAdmin on that folder and remove Development IAM bindings from each project manually.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot