Professional Cloud Security EngineerManaging operationsHard

An organization is migrating sensitive data to Google Cloud Storage. As per their internal security policy, they must ensure that all newly created Cloud Storage buckets are encrypted with Customer-Managed Encryption Keys (CMEK) by default. Any deviation from this policy should be flagged immediately. Which Google Cloud service should be configured to enforce this policy at the organization level?

  1. ASecurity Health Analytics to identify non-compliant buckets.
  2. BOrganization Policy Service with a custom constraint.
  3. CCloud Logging with a log sink to detect bucket creation events.
  4. DCloud Monitoring to alert on unencrypted buckets.
Show answer & explanation

Correct answer: B. Organization Policy Service with a custom constraint.

The Organization Policy Service is designed to centrally control resource configurations across an entire Google Cloud organization. Custom constraints can be created to enforce specific behaviors, such as requiring CMEK for Cloud Storage buckets. This prevents the creation of non-compliant resources rather than just alerting on them after creation.

Why the other options are wrong

  • A. Security Health Analytics identifies existing misconfigurations or non-compliance, but it does not prevent the creation of non-compliant resources.
  • C. Cloud Logging can detect bucket creation events, but it doesn't prevent non-compliant buckets from being created. It's a reactive solution, not proactive enforcement.
  • D. Cloud Monitoring can alert on metrics, but it doesn't enforce the creation of resources with CMEK by default.

Organization Policy Service (Custom Constraints)

The Organization Policy Service allows administrators to centrally control resource configurations across a Google Cloud organization. Custom constraints extend this capability, enabling enforcement of specific, user-defined policies, such as requiring CMEK for Cloud Storage buckets.

  • Centralized control over resource configurations.
  • Enforces policies at the organization/folder/project level.
  • Custom constraints allow fine-grained, preventive policy enforcement.

Memory trick: Org Policy enforces the rules from the top.

More Managing operations questions