Professional Cloud Security EngineerEnsuring complianceEasy
A global enterprise is using Google Cloud and needs to ensure that all new Google Cloud projects are created with specific default IAM policies and billing accounts attached. They want to prevent project creators from bypassing these defaults. Which Google Cloud service should they use to enforce this requirement?
- AAccess Context Manager
- BResource Manager
- CCloud Identity
- DIdentity Platform
Show answer & explanationAnswer & explanation
Correct answer: B. Resource Manager
Resource Manager allows organizations to programmatically manage resources by project, folder, and organization. This includes setting default IAM policies and associating billing accounts at higher levels of the resource hierarchy, which new projects will inherit.
Why the other options are wrong
- A. Access Context Manager defines fine-grained, attribute-based access control, but not default project creation settings.
- C. Cloud Identity manages users and groups, not project creation policies.
- D. Identity Platform is primarily for customer-facing identity and access management for applications.
Resource Manager
Google Cloud's Resource Manager allows you to programmatically manage resources by project, folder, and organization, providing hierarchical organization and policy inheritance.
- Organizes resources hierarchically (Organization -> Folders -> Projects).
- Enables policy inheritance across the hierarchy.
- Manages IAM policies and billing accounts at various levels.
Memory trick: Resource Manager is like a 'family tree' for your cloud stuff, passing down rules.