PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #147
You want to prevent users from accidentally deleting a Shared VPC host project. Which organization-level policy constraint should you enable?
The correct answer is B. compute.restrictXpnProjectLienRemoval. https://cloud.google.com/resource-manager/docs/organization-policy/org-policy- constraints#constraints-for-specific-services - constraints/compute.restrictXpnProjectLienRemoval - Restrict shared VPC project lien removal This boolean constraint restricts the set of users that…
Question
Options
- Acompute.restrictSharedVpcHostProjects
- Bcompute.restrictXpnProjectLienRemoval
- Ccompute.restrictSharedVpcSubnetworks
- Dcompute.sharedReservationsOwnerProjects
How the community answered
(43 responses)- A5% (2)
- B70% (30)
- C19% (8)
- D7% (3)
Explanation
https://cloud.google.com/resource-manager/docs/organization-policy/org-policy- constraints#constraints-for-specific-services - constraints/compute.restrictXpnProjectLienRemoval - Restrict shared VPC project lien removal This boolean constraint restricts the set of users that can remove a Shared VPC host project lien without organization-level permission where this constraint is set to True. By default, any user with the permission to update liens can remove a Shared VPC host project lien. Enforcing this constraint requires that permission be granted at the organization level.
Topics
Community Discussion
No community discussion yet for this question.