Google Associate Cloud EngineerConfiguring access and securityHard
An internal audit reveals that several service accounts in a critical project have overly permissive roles, such as 'Editor' or 'Owner'. The security team wants to enforce a policy that prevents the creation of any new service accounts with these broad roles, and also restricts existing service accounts from being granted such roles, across the entire organization. Which Google Cloud feature should they use?
- AIAM Conditions
- BOrganization Policy Constraints
- CCustom IAM Roles
- DCloud Asset Inventory
Show answer & explanationAnswer & explanation
Correct answer: B. Organization Policy Constraints
Organization Policy Constraints allow administrators to define guardrails for resource creation and configuration across an entire organization. Specifically, the 'Restrict service account usage' constraint can prevent service accounts from being created with or granted overly permissive roles like Editor or Owner, enforcing the principle of least privilege at an organizational level.
Why the other options are wrong
- A. IAM Conditions allow conditional role bindings based on attributes like time or resource tags, but don't prevent the binding of broad roles at an organizational level.
- C. Custom IAM Roles help create granular permissions but don't prevent users from granting broad predefined roles to service accounts.
- D. Cloud Asset Inventory provides a history and metadata of cloud resources but does not enforce policies or prevent actions.
Organization Policy Constraints
Organization Policy Constraints allow administrators to define rules that restrict the configuration of Google Cloud resources across an entire organization, folders, or projects.
- Enforce compliance and security policies at a high level.
- Applied to organizations, folders, or projects.
- Can restrict resource creation, IAM bindings, API usage, and more.
Memory trick: Organization Policies are the gatekeepers for the whole kingdom.