An enterprise administrator needs to ensure that no virtual machines created within a specific folder can be assigned external IP addresses. Which Google Cloud service or feature should be configured on the folder to enforce this restriction across all descendant projects?
- An Organization Policy constraint restricting external IP accessCevap
- BAn IAM role binding that grants the Compute Viewer role to all project members
- CA primitive Owner role assigned at the organization level with customized exclusions
- DAn IAM permission revocation on child project resources to override folder-level access
Cevap
An Organization Policy constraint applied at the folder level enforces restrictions on resource configurations across all child projects.
Organization Policies enable administrators to set centralized configuration guardrails across the Google Cloud resource hierarchy. Applying an Organization Policy constraint at the folder level automatically enforces the restriction across all projects inherited by that folder.
Adım Adım Çözüm
Anahtar Kavram
Organization Policies enforce governance constraints on resources across the GCP resource hierarchy.