GCP Professional Cloud Security Engineer Practice Question
Your financial-services firm has 100+ Google Cloud projects under a single organization. To meet new PCI DSS rules, security requires that: 1) any new Compute Engine VM must launch without an external (public) IP, and 2) no new service-account keys may be created. Enforcement must be automatic for all current and future projects, yet the central security team must be able to grant a short exception to a specific project when necessary. As the security engineer, which approach best meets these goals while minimizing effort?
Move every project into a Shared VPC where internet egress is disabled and strip the serviceAccount.keys.create permission from all IAM roles at the organization level; re-grant the permission in projects that need an exception.
Define organization policies at the organization root that enforce the constraints "compute.vmExternalIpAccess" (deny all) and "iam.disableServiceAccountKeyCreation". Use policy inheritance so the security team can override either constraint at a specific project or folder when an approved exception is needed.
Deploy a centralized Cloud Function triggered by Cloud Audit Logs that deletes any VM with an external IP or any newly created service account key; modify the function's allowlist in Firestore whenever an exception is required.
Create a VPC Service Controls perimeter that blocks egress to 0.0.0.0/0 for every project and add a custom constraint that prevents assigning the iam.serviceAccountKeyAdmin role; temporarily remove the project from the perimeter and role restriction to grant an exception.
Organization Policy constraints are preventive controls that apply automatically to every project created under the part of the resource hierarchy where they are set. By setting the constraint "compute.vmExternalIpAccess" to deny all external IP creation and enabling the boolean constraint "iam.disableServiceAccountKeyCreation" at the organization root, the company prevents both public IP assignment to new VMs and creation of new service-account keys across every current and future project. Because Organization Policies are inheritable but can be overridden lower in the hierarchy, the security team can create a less-restrictive policy on a specific folder or project (for example, by clearing the deny list or turning off enforcement) to grant a temporary, auditable exception and then re-enable the stricter policy when no longer needed. The other approaches rely on reactive remediation, fail to block external IPs, or cannot comprehensively prevent key creation, so they do not meet the preventive and low-overhead requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Organization Policies in GCP?
Open an interactive chat with Bash
How does the 'compute.vmExternalIpAccess' constraint work in GCP?
Open an interactive chat with Bash
What is the 'iam.disableServiceAccountKeyCreation' constraint in GCP?
Open an interactive chat with Bash
What are Organization Policies in Google Cloud?
Open an interactive chat with Bash
How does inheritance work in Organization Policies?
Open an interactive chat with Bash
What is PCI DSS, and why is it important in cloud security?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .