Google
PROFESSIONAL-CLOUD-ARCHITECT · Question #264
Your company has just recently activated Cloud Identity to manage users. The Google Cloud Organization has been configured as well. The security team needs to secure projects that will be part of the
The correct answer is A. Configure an organization policy to restrict identities by domain.. https://cloud.google.com/resource-manager/docs/organization-policy/restricting-domains
Submitted by tom_us· Mar 30, 2026Designing for security and compliance
Question
Your company has just recently activated Cloud Identity to manage users. The Google Cloud Organization has been configured as well. The security team needs to secure projects that will be part of the Organization. They want to prohibit IAM users outside the domain from gaining permissions from now on. What should they do?
Options
- AConfigure an organization policy to restrict identities by domain.
- BConfigure an organization policy to block creation of service accounts.
- CConfigure Cloud Scheduler to trigger a Cloud Function every hour that removes all users that
- DCreate a technical user (e.g., [email protected]), and give it the project owner role at root
How the community answered
(30 responses)- A93% (28)
- B3% (1)
- D3% (1)
Explanation
https://cloud.google.com/resource-manager/docs/organization-policy/restricting-domains
Topics
#organization policy#IAM#domain restriction#Cloud Identity
Community Discussion
No community discussion yet for this question.