Professional Cloud Security EngineerEnsuring complianceEasy

A global financial institution is implementing Google Cloud and needs to enforce specific resource configurations across its entire organization. They require that all new projects automatically prohibit the creation of external IP addresses on virtual machines and ensure that all Cloud Storage buckets are created with uniform bucket-level access. Which Google Cloud service should they use to define and enforce these constraints consistently?

  1. AOrganization Policy Service
  2. BCloud IAM
  3. CResource Manager
  4. DSecurity Command Center
Show answer & explanation

Correct answer: A. Organization Policy Service

Organization Policy Service allows administrators to programmatically control their organization's cloud resources. It provides centralized control over an organization's Google Cloud resources, enabling the enforcement of constraints like disabling external IPs or enforcing uniform bucket-level access.

Why the other options are wrong

  • B. Cloud IAM manages who can do what on which resources, not the properties of the resources themselves.
  • C. Resource Manager organizes resources hierarchically but does not enforce configuration constraints.
  • D. Security Command Center is a security management and data risk platform that helps prevent, detect, and respond to threats, not enforce resource configurations.

Organization Policy Service

A Google Cloud service that enables centralized control over an organization's resources by defining and enforcing constraints on their configuration.

  • Enforces constraints at the organization, folder, or project level.
  • Helps achieve compliance and security best practices.
  • Prevents creation of non-compliant resources.

Memory trick: Org Policies are the 'Guardians of Google Cloud', ensuring everything aligns with the rules.

More Ensuring compliance questions