🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 26 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization is migrating its card-holder data environment to Google Cloud. Security and compliance teams have issued the following mandatory controls for every project that will reside in the existing "prod" folder:

  1. No new Compute Engine VMs may be created with an external (ephemeral or static) IPv4 address.
  2. All Cloud SQL instances must be created without a public IP address.
  3. Any new regional or multiregional resource must be located only in europe-west2, europe-west3, or europe-north1. You need to implement these controls so they apply immediately to the current projects in the prod folder and automatically to any projects that will be created under that folder in the future. Other folders must remain unaffected. Which combination of Organization Policy constraints and settings meets all of the stated requirements?
  • Apply compute.vmExternalIpAccess with enforce: true, use the sql.disablePublicIp constraint, and allow only the EU multi-region in gcp.resourceLocations at the organization root.

  • Set compute.vmExternalIpAccess to allow all values, leave sql.restrictPublicIp disabled, and configure gcp.resourceLocations with a deny list that excludes us-* and asia-* regions on each individual project.

  • Enable the compute.requireOsLogin constraint, create an Assured Workloads EU environment for the prod folder, and apply the restrictXpnProjectLien constraint to all child projects.

  • On the prod folder, deny all values for the compute.vmExternalIpAccess list constraint, enforce the sql.restrictPublicIp boolean constraint, and configure gcp.resourceLocations with an allowed list limited to europe-west2, europe-west3, and europe-north1.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot