Soru

Zorluk: OrtaConfiguring Organization Policies and Resource Hierarchy Constraints

A cloud security administrator needs to prevent Compute Engine VM instances from being assigned external IP addresses across all projects contained within the 'Engineering' folder. Additionally, one specific testing project inside that folder requires external IPs for synthetic user testing. Which two steps must the administrator take to configure this resource hierarchy constraint correctly?

  1. Apply the organization policy constraint restricting external IP access at the 'Engineering' folder level.Cevap
  2. B
    Grant the Organization Policy Administrator role to the Compute Engine default service account to automatically enforce the network rule.
  3. Override the inherited organization policy on the specific testing project node to allow external IP address assignment.Cevap
  4. D
    Create an IAM Deny policy at the folder level and rely on IAM inheritance to prevent projects from requesting external IP addresses.

Cevap

To enforce this configuration, the administrator must apply the organization policy constraint at the folder level to cover all child projects by default, and then override the inherited policy directly on the testing project node to permit external IPs.
Applying the organization policy constraint at the folder level ensures that all projects within the 'Engineering' folder inherit the external IP restriction. To grant the necessary exception, overriding the policy at the specific testing project node allows external IP allocation without breaking compliance for the rest of the folder.

Adım Adım Çözüm

1
Identify the resource hierarchy scope for the baseline restriction.
The baseline constraint must apply broadly to all projects under the 'Engineering' folder.
Setting organization policies at higher nodes in the hierarchy ensures consistent governance across child resources.
2
Apply the external IP restriction policy at the folder level.
All projects inside the 'Engineering' folder inherit the restriction.
GCP Organization Policies evaluate down the resource hierarchy tree.
3
Configure a policy override at the targeted child project level.
The testing project bypasses the inherited restriction while keeping other projects secure.
Explicit project-level policy rules take precedence over inherited parent folder rules when inheritance is overridden.

Anahtar Kavram

GCP Organization Policies allow central governance across the resource hierarchy (Organization -> Folder -> Project), where inherited policies can be overridden at lower nodes to accommodate specific project exceptions.
Tahmini Süre:1m 30s
Bu soruyu puanla