nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #149

You are a security administrator at your company. Per Google-recommended best practices, you implemented the domain restricted sharing organization policy to allow only required domains to access…

The correct answer is D. Turn off the domain restricted sharing organization policy. Set the policy value to "Custom." Add. https://cloud.google.com/resource-manager/docs/organization-policy/restricting- domains#setting_the_organization_policy The domain restriction constraint is a type of list constraint. Google Workspace customer IDs can be added and removed from the allowed_values list of a…

Submitted by takeshi77· Apr 18, 2026Configuring access within a cloud solution environment

Question

You are a security administrator at your company. Per Google-recommended best practices, you implemented the domain restricted sharing organization policy to allow only required domains to access your projects. An engineering team is now reporting that users at an external partner outside your organization domain cannot be granted access to the resources in a project. How should you make an exception for your partner's domain while following the stated best practices?

Options

  • ATurn off the domain restriction sharing organization policy. Set the policy value to "Allow All."
  • BTurn off the domain restricted sharing organization policy. Provide the external partners with the
  • CTurn off the domain restricted sharing organization policy. Add each partner's Google Workspace
  • DTurn off the domain restricted sharing organization policy. Set the policy value to "Custom." Add

How the community answered

(60 responses)
  • A
    10% (6)
  • B
    5% (3)
  • C
    2% (1)
  • D
    83% (50)

Explanation

https://cloud.google.com/resource-manager/docs/organization-policy/restricting- domains#setting_the_organization_policy The domain restriction constraint is a type of list constraint. Google Workspace customer IDs can be added and removed from the allowed_values list of a domain restriction constraint. The domain restriction constraint does not support denying values, and an organization policy can't be saved with IDs in the denied_values list. All domains associated with a Google Workspace account listed in the allowed_values will be allowed by the organization policy. All other domains will be denied by the organization policy.

Topics

#Organization Policy#Domain Restricted Sharing#External Access Control#IAM Best Practices

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice