nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #153

Your company's Chief Information Security Officer (CISO) creates a requirement that business data must be stored in specific locations due to regulatory requirements that affect the company's global…

The correct answer is C. Project. The correct level is Project (C). The key clue is that 'the folder structure can contain multiple data residency locations,' meaning different projects within the same folder may need different allowed regions. Setting the constraint at the Organization level (D) would force a…

Submitted by fatima_kr· Apr 18, 2026Ensuring compliance

Question

Your company's Chief Information Security Officer (CISO) creates a requirement that business data must be stored in specific locations due to regulatory requirements that affect the company's global expansion plans. After working on the details to implement this requirement, you determine the following: - The services in scope are included in the Google Cloud Data Residency Terms. - The business data remains within specific locations under the same organization. - The folder structure can contain multiple data residency locations. You plan to use the Resource Location Restriction organization policy constraint. At which level in the resource hierarchy should you set the constraint?

Options

  • AFolder
  • BResource
  • CProject
  • DOrganization

How the community answered

(49 responses)
  • A
    14% (7)
  • B
    8% (4)
  • C
    73% (36)
  • D
    4% (2)

Explanation

The correct level is Project (C). The key clue is that 'the folder structure can contain multiple data residency locations,' meaning different projects within the same folder may need different allowed regions. Setting the constraint at the Organization level (D) would force a single global policy with no flexibility for different regions across projects. Setting it at the Folder level (A) is still too broad if different projects within the folder need different regions. The Project level gives the most granular control, allowing each project to have its own Resource Location Restriction policy tailored to its specific regulatory requirement, while still cascading the constraint down to all resources within that project. Setting it at the Resource level (B) is not a valid scope for this organization policy constraint.

Topics

#Data Residency#Organization Policy#Resource Hierarchy#Compliance Enforcement

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice