Professional Cloud Security EngineerEnsuring complianceMedium

A large pharmaceutical company uses Google Cloud for its sensitive research data. They need to ensure strict data residency, preventing any data from leaving specific geographical regions. They also want to enforce consistent security configurations across all new projects created within their organization, such as disabling public IP addresses for VMs. Which Google Cloud service combination is best suited for these requirements?

  1. AAccess Transparency and Binary Authorization
  2. BOrganization Policy Service and Resource Manager
  3. CVPC Service Controls and Cloud Identity
  4. DCloud Armor and Security Command Center
Show answer & explanation

Correct answer: B. Organization Policy Service and Resource Manager

Organization Policy Service allows administrators to programmatically control Google Cloud resources across an organization, including constraints on resource locations (data residency) and disabling public IP addresses. Resource Manager organizes resources hierarchically, which is where these policies are applied.

Why the other options are wrong

  • A. Access Transparency provides logs of Google personnel access, and Binary Authorization enforces deployment policies for images. Neither addresses data residency or VM configuration at an organizational level.
  • C. VPC Service Controls protect against data exfiltration but don't define resource locations or enforce specific VM configurations across an organization. Cloud Identity manages users and groups.
  • D. Cloud Armor is a WAF for DDoS and XSS protection. Security Command Center is for threat detection and vulnerability management. Neither is used for organizational policy enforcement on resource locations or VM configurations.

Organization Policy Service

A service that provides centralized programmatic control over an organization's Google Cloud resources, allowing administrators to define constraints on resource configurations and behaviors.

  • Enforces compliance across the entire resource hierarchy.
  • Prevents unintended changes to resource configurations.
  • Commonly used for data residency and network security policies.

Memory trick: Org Policy is the CEO's rulebook, applied by the Resource Manager.

More Ensuring compliance questions