🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 51 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company operates a single Google Cloud organization with hundreds of projects. A new EU subsidiary must ensure all new and existing resources in its prod-eu folder stay within EU regions, while all other folders remain unrestricted. As the security engineer, which action best enforces this data-residency requirement with minimal administrative overhead?

  • Define the constraints/gcp.resourceLocations policy at the organization root to allow only EU regions and the eu multi-region so that all descendants inherit the restriction.

  • Create a VPC Service Controls perimeter for the prod-eu folder that lists EU regions; this will automatically prevent creation of resources outside the EU, eliminating the need for an Organization Policy.

  • Do not configure a location policy at the organization level. Instead, attach the predefined constraints/gcp.resourceLocations policy to the prod-eu folder with inherit_from_parent set to false and specify only EU regions or the eu multi-region as allowed values.

  • Keep the organization-level policy unset, create a custom location constraint, attach it to the prod-eu folder, and allow only EU regions.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot