Professional Cloud Security EngineerEnsuring complianceHard

A security architect needs to implement a policy that restricts the creation of any new Google Cloud Storage (GCS) buckets outside of specific regions (e.g., 'us-central1', 'us-east1') across the entire organization. They also want to ensure that all GCS buckets are created with Uniform bucket-level access enabled by default. Which Google Cloud service should be used to enforce these two requirements consistently?

  1. AVPC Service Controls with ingress/egress rules.
  2. BCloud IAM with custom roles.
  3. COrganization Policy Service with custom constraints.
  4. DCloud Storage bucket policies.
Show answer & explanation

Correct answer: C. Organization Policy Service with custom constraints.

Organization Policy Service allows you to define constraints at the organizational level. For restricting GCS bucket locations, you use the `constraints/gcp.resourceLocations` constraint. For enforcing Uniform bucket-level access, you would typically use `constraints/storage.uniformBucketLevelAccess` or a custom constraint if more specific logic is needed, applying them across the organization.

Why the other options are wrong

  • A. VPC Service Controls protect against data exfiltration and define service perimeters, but they don't directly enforce resource creation location or uniform bucket access as an organizational policy.
  • B. Cloud IAM manages *who can do what*, not *what can be done* regarding resource configurations like location or uniform access policies.
  • D. Cloud Storage bucket policies are set per bucket, which doesn't provide the organization-wide enforcement required for new buckets by default.

Organization Policy Custom Constraints

Beyond predefined constraints, Organization Policy Service allows creating custom constraints to enforce specific, granular policies tailored to an organization's unique compliance needs across Google Cloud resources.

  • Extends the power of Organization Policy Service.
  • Defined using Common Expression Language (CEL).
  • Can enforce complex rules on resource properties.

Memory trick: Org Policy is the 'CEO Policy' for all new resources.

More Ensuring compliance questions