🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 26 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company, which uses the Cloud Identity domain corp.example, runs dozens of projects under one Google Cloud organization. A new Payment-Processing folder must meet PCI-DSS requirements that mandate every IAM principal in that folder belong only to corp.example. Other folders may continue granting roles to partner.com users. Which action will enforce this requirement on the Payment-Processing folder without impacting the rest of the organization?

  • Add IAM deny policies to each project in the Payment-Processing folder that exclude any principal whose email does not end with @corp.example.

  • Enable Access Approval on the Payment-Processing folder and reject any approval requests that originate from partner.com accounts.

  • Create a VPC Service Controls perimeter for the Payment-Processing folder and configure an access level that admits only corp.example identities.

  • Apply the Organization Policy constraint "constraints/iam.allowedPolicyMemberDomains" to the Payment-Processing folder, allowing only the corp.example domain and leaving the constraint unset at higher levels.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot