GCP Professional Cloud Security Engineer Practice Question

ExampleCorp has six product lines that spin up dozens of GCP projects every quarter. Compliance must enforce VM external-IP restrictions only for production workloads. Product-line administrators must self-provision new projects for their line without obtaining organization-level roles. Project names must follow a standard pattern and inherit the required constraints automatically. You want the central security team to stay out of the provisioning path while retaining policy control. Which approach best meets these requirements?

  • Establish two Google Cloud organizations-one for production and one for non-production-and grant product-line admin groups the Organization Administrator role in each so they can create projects directly.

  • Have the central security team create every project manually, move it into the right folder, apply the external-IP constraint, and then assign admin roles to the product-line group.

  • Create separate production and non-production folders, add a sub-folder per product line, grant each product-line admin group roles/resourcemanager.folderAdmin and roles/resourcemanager.projectCreator on its sub-folder, apply the VM external-IP Organization Policy constraint to the production folder, and use an automated pipeline that creates correctly named projects inside the appropriate sub-folder.

  • Grant each product-line admin group the Project Creator role at the organization level and apply the external-IP constraint to projects after creation by using tag-based policies.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot