Professional Cloud Security EngineerEnsuring complianceEasy

A large enterprise is migrating its on-premises applications to Google Cloud. The security team needs to ensure that only approved virtual machine images are deployed across all projects, preventing the use of images that have not gone through their internal security vetting process. This requirement applies to all new deployments from development to production environments. Which Google Cloud service should they use to enforce this policy effectively?

  1. ACloud Asset Inventory
  2. BCloud Build
  3. CSecurity Command Center
  4. DOrganization Policy Service
Show answer & explanation

Correct answer: D. Organization Policy Service

Organization Policy Service allows administrators to set constraints across the entire Google Cloud organization, including policies that restrict the types of VM images that can be used. This directly addresses the requirement to ensure only approved images are deployed.

Why the other options are wrong

  • A. Cloud Asset Inventory provides a history of cloud assets but does not enforce policies.
  • B. Cloud Build is a continuous integration/delivery platform and does not enforce image usage policies at the organization level.
  • C. Security Command Center is used for security management and risk assessment, not for enforcing resource creation policies.

Organization Policy Service

A service that allows Google Cloud administrators to programmatically control their organization's cloud resources, enabling centralized governance and compliance.

  • Enforces policies across projects and folders.
  • Supports predefined and custom constraints.
  • Helps achieve compliance and security objectives.

Memory trick: Organization's Policies: The Boss of All Projects.

More Ensuring compliance questions