A security operations team wants to ensure that no virtual machines created within a development Folder can be assigned public IP addresses. This rule must automatically apply to all current and future projects inside that folder. Which configuration should be used to enforce this restriction?
- Apply an Organization Policy constraint at the Folder level to restrict public IP addresses.Cevap
- BAssign a predefined IAM Security Reviewer role to developers at the Folder level.
- CRevoke primitive Viewer permissions from developers across all child projects.
- DAdd an IAM Deny policy on individual child projects to override resource permissions inherited from the Folder.
Cevap
Apply an Organization Policy constraint at the Folder level to restrict public IP addresses.
Organization Policies provide centralized, programmatic control over cloud resources. Applying an Organization Policy constraint at the Folder level automatically applies the restriction to all existing and newly created child projects within that folder.
Adım Adım Çözüm
Anahtar Kavram
Organization Policy Constraints and Resource Hierarchy Inheritance
Tahmini Süre:45s