Professional Cloud Security EngineerEnsuring complianceHard
A global manufacturing company uses Google Cloud and has stringent compliance requirements. They need to ensure that specific types of resources, such as high-performance compute instances or certain database types, are only created within designated projects and never within others, even if a user has IAM permissions to create them. Which Google Cloud service, combined with custom constraints, can enforce this requirement?
- AVPC Service Controls
- BSecurity Command Center
- CCloud Asset Inventory
- DOrganization Policy Service
Show answer & explanationAnswer & explanation
Correct answer: D. Organization Policy Service
Organization Policy Service, especially with custom constraints, allows organizations to define rules that restrict resource creation based on criteria like resource type and project location. This can prevent the creation of specific resources in unauthorized projects, overriding IAM permissions if necessary.
Why the other options are wrong
- A. VPC Service Controls creates security perimeters to prevent data exfiltration, not to restrict resource creation types based on project.
- B. Security Command Center monitors for violations and vulnerabilities, but doesn't prevent resource creation based on custom rules.
- C. Cloud Asset Inventory provides a database of cloud assets but doesn't enforce policies on resource creation.
Organization Policy Service
Organization Policy Service allows Google Cloud administrators to centrally control resource configuration across their organization, defining constraints on how resources can be used and created.
- Enforces rules at the Organization, Folder, or Project level.
- Can restrict resource creation, network configurations, and more.
- Supports custom constraints for highly specific policy enforcement.
Memory trick: Organization Policy is like the 'CEO' of rules, telling everyone what they can and can't build.