GCP Professional Data Engineer Practice Question

An international bank has a Google Cloud organization with two top-level folders: Payments (EU production workloads) and Sandbox (experimentation). Project owners in both folders can create Cloud Storage buckets and BigQuery datasets. All new resources under the Payments folder must reside only in regions europe-west1 or europe-west4, while Sandbox projects should remain unrestricted. You must enforce this rule even for users who hold the Owner role and want to minimize ongoing operational effort. What should you do?

  • Create a deny policy on "constraints/gcp.resourceLocations" at the organization root that blocks every region except europe-west1 and europe-west4, relying on inheritance for enforcement.

  • Configure an Audit Log sink that triggers a Cloud Function to delete any bucket or dataset under Payments that is created outside europe-west1 or europe-west4.

  • Attach an Organization Policy for the constraint "constraints/gcp.resourceLocations" to the Payments folder, specifying only ["europe-west1", "europe-west4"] as allowed values and leaving the Sandbox folder without this policy.

  • Define a VPC Service Controls perimeter around the Payments folder that permits only europe-west1 and europe-west4 egress endpoints.

GCP Professional Data Engineer
Designing data processing systems
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot