nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #158

Your company's chief information security officer (CISO) is requiring business data to be stored in specific locations due to regulatory requirements that affect the company's global expansion…

The correct answer is C. Project. To implement granular data residency requirements using the Resource Location Restriction organization policy constraint when projects are aligned to specific locations, the constraint should be set at the Project level.

Submitted by brentm· Apr 18, 2026Ensuring compliance

Question

Your company's chief information security officer (CISO) is requiring business data to be stored in specific locations due to regulatory requirements that affect the company's global expansion plans. After working on a plan to implement this requirement, you determine the following: - The services in scope are included in the Google Cloud data residency requirements. - The business data remains within specific locations under the same organization. - The folder structure can contain multiple data residency locations. - The projects are aligned to specific locations. You plan to use the Resource Location Restriction organization policy constraint with very granular control. At which level in the hierarchy should you set the constraint?

Options

  • AOrganization
  • BResource
  • CProject
  • DFolder

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    18% (5)
  • C
    71% (20)
  • D
    7% (2)

Why each option

To implement granular data residency requirements using the Resource Location Restriction organization policy constraint when projects are aligned to specific locations, the constraint should be set at the Project level.

AOrganization

Setting the constraint at the Organization level would apply the restriction across all projects and folders, which conflicts with the need for granular control and folders potentially containing multiple data residency locations.

BResource

Resource is too granular and not a direct level for setting organization policies; organization policies are applied at Organization, Folder, or Project levels.

CProjectCorrect

Setting the Resource Location Restriction organization policy constraint at the Project level provides the most granular control, aligning with the requirement that "projects are aligned to specific locations." This allows for different location restrictions to be applied to different projects, even if they reside within the same folder, which can contain multiple data residency locations. This level of control ensures that data for each project stays within its designated geographical boundary as per regulatory requirements.

DFolder

Setting the constraint at the Folder level would apply the restriction to all projects within that folder, which might not be granular enough if projects within the same folder have different location requirements.

Concept tested: Google Cloud Resource Location Restriction Policy Granularity

Source: https://cloud.google.com/resource-manager/docs/organization-policy/defining-locations

Topics

#Data Residency#Organization Policy#Resource Hierarchy#Regulatory Compliance

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice