Professional Cloud Security EngineerConfiguring access within a cloud solution environmentHard
A security auditor needs to ensure that no project in the organization can grant the `roles/owner` role to external users (users outside the organization's primary domain). The auditor also wants to enforce that service accounts cannot be granted `roles/editor` or `roles/owner` roles at the project level. Which Google Cloud service or feature should be used to enforce these restrictions across the entire organization?
- AIAM Conditions
- BCloud Audit Logs
- CCustom IAM Roles
- DOrganization Policies
Show answer & explanationAnswer & explanation
Correct answer: D. Organization Policies
Organization Policies allow administrators to programmatically control Google Cloud resources across an entire organization. Specifically, the `constraints/iam.allowedPolicyMemberDomains` constraint can restrict which domains can be added to IAM policies, and `constraints/iam.disableServiceAccountKeyCreation` along with custom constraints can enforce restrictions on roles granted to service accounts.
Why the other options are wrong
- A. IAM Conditions apply to individual IAM policy bindings and are not suitable for enforcing organization-wide restrictions on who can be granted certain roles or what roles can be granted to service accounts.
- B. Cloud Audit Logs record administrative activities but do not prevent actions from occurring; they are for auditing after the fact.
- C. Custom IAM Roles define specific sets of permissions but do not prevent the assignment of broader predefined roles or restrict external users at an organizational level.
Organization Policies
A Google Cloud service that allows administrators to programmatically control Google Cloud resources across an entire organization, defining guardrails and restrictions.
- Applied at the Organization, Folder, or Project level.
- Uses constraints to enforce rules (e.g., `list_allowed_values`, `true_false`).
- Essential for central governance and compliance.
Memory trick: Organization Policies Orchestrate Overall Protection.