Professional Cloud Security EngineerConfiguring access within a cloud solution environmentHard

A security auditor needs to ensure that no project in the organization can grant the `roles/owner` role to external users (users outside the organization's primary domain). The auditor also wants to enforce that service accounts cannot be granted `roles/editor` or `roles/owner` roles at the project level. Which Google Cloud service or feature should be used to enforce these restrictions across the entire organization?

  1. AIAM Conditions
  2. BCloud Audit Logs
  3. CCustom IAM Roles
  4. DOrganization Policies
Show answer & explanation

Correct answer: D. Organization Policies

Organization Policies allow administrators to programmatically control Google Cloud resources across an entire organization. Specifically, the `constraints/iam.allowedPolicyMemberDomains` constraint can restrict which domains can be added to IAM policies, and `constraints/iam.disableServiceAccountKeyCreation` along with custom constraints can enforce restrictions on roles granted to service accounts.

Why the other options are wrong

  • A. IAM Conditions apply to individual IAM policy bindings and are not suitable for enforcing organization-wide restrictions on who can be granted certain roles or what roles can be granted to service accounts.
  • B. Cloud Audit Logs record administrative activities but do not prevent actions from occurring; they are for auditing after the fact.
  • C. Custom IAM Roles define specific sets of permissions but do not prevent the assignment of broader predefined roles or restrict external users at an organizational level.

Organization Policies

A Google Cloud service that allows administrators to programmatically control Google Cloud resources across an entire organization, defining guardrails and restrictions.

  • Applied at the Organization, Folder, or Project level.
  • Uses constraints to enforce rules (e.g., `list_allowed_values`, `true_false`).
  • Essential for central governance and compliance.

Memory trick: Organization Policies Orchestrate Overall Protection.

More Configuring access within a cloud solution environment questions