PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #368
Your organization enforces a custom organization policy that disables the use of Compute Engine VM instances with external IP addresses. However, a regulated business unit requires an exception to…
The correct answer is C. Apply the custom organization policy at the organization level to restrict external IPs. Move the. The correct approach is to apply the restrictive policy at the organization level for consistent enforcement and then create a folder for the regulated business unit where you override the policy to temporarily allow external IPs. This follows the principle of least privilege…
Question
Options
- ACreate a folder. Apply the restrictive organization policy for non-regulated business workloads in
- BApply the restrictive organization policy at the organization level. Create an IAM custom role with
- CApply the custom organization policy at the organization level to restrict external IPs. Move the
- DModify the custom organization policy at the organization level to allow external IPs for all projects.
How the community answered
(21 responses)- A14% (3)
- B5% (1)
- C76% (16)
- D5% (1)
Explanation
The correct approach is to apply the restrictive policy at the organization level for consistent enforcement and then create a folder for the regulated business unit where you override the policy to temporarily allow external IPs. This follows the principle of least privilege, minimizes organization-wide policy drift, and confines the exception to only the regulated workload.
Topics
Community Discussion
No community discussion yet for this question.