nerdexam
Google

PROFESSIONAL-CLOUD-ARCHITECT · Question #264

Your company has just recently activated Cloud Identity to manage users. The Google Cloud Organization has been configured as well. The security team needs to secure projects that will be part of the

The correct answer is A. Configure an organization policy to restrict identities by domain.. https://cloud.google.com/resource-manager/docs/organization-policy/restricting-domains

Submitted by tom_us· Mar 30, 2026Designing for security and compliance

Question

Your company has just recently activated Cloud Identity to manage users. The Google Cloud Organization has been configured as well. The security team needs to secure projects that will be part of the Organization. They want to prohibit IAM users outside the domain from gaining permissions from now on. What should they do?

Options

  • AConfigure an organization policy to restrict identities by domain.
  • BConfigure an organization policy to block creation of service accounts.
  • CConfigure Cloud Scheduler to trigger a Cloud Function every hour that removes all users that
  • DCreate a technical user (e.g., [email protected]), and give it the project owner role at root

How the community answered

(30 responses)
  • A
    93% (28)
  • B
    3% (1)
  • D
    3% (1)

Explanation

https://cloud.google.com/resource-manager/docs/organization-policy/restricting-domains

Topics

#organization policy#IAM#domain restriction#Cloud Identity

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-ARCHITECT Practice