GCP Professional Cloud Security Engineer Practice Question

Your organization manages dozens of Google Cloud projects under a single organization node. Security has issued these directives:

  1. No VM in any project may have an external IPv4 address, except the project called "legacy-project", which still requires one during migration.
  2. IAM policies anywhere in the hierarchy must reference only principals from the company domain (corp.example) or the partner domain (partner.example). Which configuration best satisfies both requirements while minimizing ongoing administrative overhead?
  • Enable VPC Service Controls around all projects to block external IP usage and configure Domain Restricted Sharing individually on every project.

  • Set the compute.vmExternalIpAccess constraint to deny all external IPs at the organization level and override it in legacy-project to allow external IPs; set the iam.allowedPolicyMemberDomains constraint at the organization level to allow only corp.example and partner.example.

  • Create an organization-wide egress firewall rule blocking 0.0.0.0/0 and use Access Context Manager service perimeters to limit IAM principals to corp.example and partner.example.

  • Apply compute.vmExternalIpAccess to allow external IPs only on legacy-project and set Domain Restricted Sharing on the finance folder; leave other projects with default settings.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot