nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #368

Your organization enforces a custom organization policy that disables the use of Compute Engine VM instances with external IP addresses. However, a regulated business unit requires an exception to…

The correct answer is C. Apply the custom organization policy at the organization level to restrict external IPs. Move the. The correct approach is to apply the restrictive policy at the organization level for consistent enforcement and then create a folder for the regulated business unit where you override the policy to temporarily allow external IPs. This follows the principle of least privilege…

Submitted by tunde_lagos· Apr 18, 2026Ensuring compliance

Question

Your organization enforces a custom organization policy that disables the use of Compute Engine VM instances with external IP addresses. However, a regulated business unit requires an exception to temporarily use external IPs for a third-party audit process. The regulated business workload must comply with least privilege principles and minimize policy drift. You need to ensure secure policy management and proper handling. What should you do?

Options

  • ACreate a folder. Apply the restrictive organization policy for non-regulated business workloads in
  • BApply the restrictive organization policy at the organization level. Create an IAM custom role with
  • CApply the custom organization policy at the organization level to restrict external IPs. Move the
  • DModify the custom organization policy at the organization level to allow external IPs for all projects.

How the community answered

(21 responses)
  • A
    14% (3)
  • B
    5% (1)
  • C
    76% (16)
  • D
    5% (1)

Explanation

The correct approach is to apply the restrictive policy at the organization level for consistent enforcement and then create a folder for the regulated business unit where you override the policy to temporarily allow external IPs. This follows the principle of least privilege, minimizes organization-wide policy drift, and confines the exception to only the regulated workload.

Topics

#Organization Policies#Policy Management#Resource Hierarchy#Least Privilege

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice