GCP Professional Cloud Security Engineer Practice Question

Your organization is subject to an EU-only data-residency mandate. You are building a new Google Cloud hierarchy that will contain many projects running Compute Engine VMs, Dataflow jobs, Cloud Storage buckets, and BigQuery datasets. Compliance asks for one centrally managed control, applied as high in the hierarchy as possible, that technically blocks creation of any future resource outside EU regions while still allowing teams to pick any individual EU region or the "eu" multi-region. Which solution satisfies these requirements?

  • Enable Assured Workloads with the EU compliance regime in every project to automatically limit resource locations to the EU.

  • Mandate an "EU_ONLY" label on every project and schedule a Cloud Function to delete resources it finds in non-EU regions.

  • Apply the Organization Policy constraint "constraints/gcp.resourceLocations" at the organization root and allow only europe-* zones and the "eu" multi-region.

  • Create a single VPC Service Controls perimeter for all projects and restrict ingress and egress to European IP ranges.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot