Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium

A security team is implementing a new policy for API key management. They want to ensure that all newly created API keys are restricted to specific IP addresses (e.g., from their corporate VPN) and only allowed to call a predefined set of APIs (e.g., Maps API, Geocoding API). This restriction must be enforced at the time of key creation and apply automatically. How can the security engineer implement this policy?

  1. AImplement Identity Platform to manage API key access controls.
  2. BApply an Organization Policy Constraint that restricts new API key creations based on IP address and API service restrictions.
  3. CUse a custom IAM role that denies the creation of unrestricted API keys.
  4. DManually configure IP restrictions and API restrictions for each API key after it's created.
Show answer & explanation

Correct answer: B. Apply an Organization Policy Constraint that restricts new API key creations based on IP address and API service restrictions.

Organization Policy Constraints are the primary mechanism for enforcing rules across an organization. A custom constraint can be created to enforce restrictions on API key properties, such as allowed IP addresses and API services, at the time of key creation, ensuring automatic compliance.

Why the other options are wrong

  • A. Identity Platform is for customer identity management and has no functionality to manage or restrict Google Cloud API keys.
  • C. IAM roles control *who* can perform *what actions* (e.g., create an API key), but not *what properties* the created resource (the API key) must have. A custom IAM role cannot enforce restrictions on the API key's attributes directly.
  • D. Manual configuration is error-prone, not scalable, and does not enforce the restriction *at the time of creation* automatically.

API Key Restrictions (Organization Policy)

Enforcing rules on API keys, such as allowed IP addresses or API services, across an organization using Organization Policy Constraints.

  • Provides centralized control over API key security.
  • Prevents creation of overly permissive API keys.
  • Enforced at the organization, folder, or project level.

Memory trick: Org Policy is the 'bouncer' for 'API keys', checking their 'ID' and 'destination'.

More Configuring access within a cloud solution environment questions