A large enterprise has a complex resource hierarchy in Google Cloud, including multiple organizations, folders, and projects. They need to implement a consistent security policy across the entire organization that mandates specific network configurations, such as disallowing external IP addresses on all new virtual machines, while still allowing some flexibility for specific development projects within a designated folder. How should they design their Organization Policy Service implementation to achieve this balance?
- AApply the 'constraints/compute.disableExternalIp' policy at the Organization level and then set an 'allow' policy for the same constraint on the development folder.
- BApply the 'constraints/compute.disableExternalIp' policy at the Organization level and then use a custom organization policy to explicitly exclude the development projects.
- CApply the 'constraints/compute.disableExternalIp' policy at the Organization level and use custom IAM roles to override it for specific projects.
- DImplement a custom constraint at the Organization level that checks for external IPs and then use a custom policy tag to exempt development projects.
Show answer & explanationAnswer & explanation
Correct answer: A. Apply the 'constraints/compute.disableExternalIp' policy at the Organization level and then set an 'allow' policy for the same constraint on the development folder.
Organization policies are inherited down the resource hierarchy. To achieve the desired balance, you apply the restrictive policy at the Organization level (enforcing it broadly) and then specifically override or 'allow' that constraint at a lower level (like a folder) for the exceptions, leveraging the policy inheritance and evaluation order.
Why the other options are wrong
- B. There's no direct 'exclude projects' mechanism within a single organization policy. Overrides are done by applying a different policy value at a lower level in the hierarchy, rather than an explicit exclusion list within a single policy.
- C. IAM roles manage permissions, not direct overrides of resource configuration constraints set by Organization Policy Service.
- D. Custom policy tags are not a feature of Organization Policy Service for exemption. While custom constraints exist, the standard 'disableExternalIp' constraint is sufficient, and overriding it is done directly with another policy, not tags.
Organization Policy Hierarchy & Overrides
Organization policies are inherited downwards through the resource hierarchy (Organization > Folders > Projects), with policies at lower levels able to override or merge with policies from higher levels.
- Policies are inherited by default.
- Parent policies can be overridden or merged by child policies.
- Different constraint types (boolean, list) have different override behaviors (e.g., boolean 'false' can override 'true').
Memory trick: The family rules (Org Policy) are strict, but specific branches (Folders) can get special permission.