GCP Professional Cloud Architect Practice Question

Your company's Google Cloud projects are scattered under the "No organization" node because individual engineers created them with personal Gmail accounts. Security leadership wants to enforce company-wide IAM policies, Cloud Audit Logs exports, and Organization Policy constraints from a single root. As the newly appointed cloud architect, what is the most effective first step to establish the required control plane with minimal service disruption?

  • Grant the security team Project Owner on every existing project and use per-project IAM and Organization Policy updates scripted through Deployment Manager.

  • Set up a dedicated host project with Shared VPC and force all teams to attach their service projects to it for centralized control.

  • Provision Cloud Identity (or Google Workspace) for the company's verified domain to automatically create an Organization resource, then migrate the existing projects under it.

  • Create a top-level folder called "Corp-Root", move all projects into it, and apply IAM and Organization Policy at the folder level.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot