Professional Cloud Security EngineerConfiguring access within a cloud solution environmentHard
A security team needs to implement a policy that prevents any service account from being granted the 'roles/owner' role on any project within their Google Cloud organization. This policy must be enforced globally across all new and existing projects. Which Google Cloud IAM feature should they use to achieve this organization-wide enforcement?
- ACreate a custom role that explicitly denies `roles/owner` and apply it to all service accounts.
- BConfigure a Cloud Security Command Center (CSCC) detector to alert on `roles/owner` assignments to service accounts.
- CImplement an Organization Policy Constraint using a custom constraint to disallow the `roles/owner` role for service accounts.
- DUse IAM Conditions to restrict when `roles/owner` can be granted to service accounts.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement an Organization Policy Constraint using a custom constraint to disallow the `roles/owner` role for service accounts.
Organization Policy Constraints are used to enforce rules across all resources within an organization. A custom constraint can be created to specifically prevent the `roles/owner` role from being granted to service accounts, providing the required global enforcement.
Why the other options are wrong
- A. IAM roles grant permissions; they cannot explicitly deny them. A custom role can only define allowed permissions, not prevent other roles from being granted.
- B. CSCC detectors provide alerts but do not *prevent* the action. The requirement is to *prevent* the granting of the role, not just to be notified after it happens. This is a detection, not a prevention, control.
- D. IAM Conditions add conditional logic to IAM policies (e.g., time-based access), but they don't prevent a role from being granted *at all* across an organization; they only dictate *when* a granted role is active.
Organization Policy Constraint (IAM)
Organization Policy Constraints allow administrators to define and enforce rules (constraints) across all resources in a Google Cloud organization, such as restricting specific IAM role assignments.
- Enforces rules organization-wide.
- Can prevent specific IAM role grants.
- Applies to new and existing resources.
Memory trick: Organization policies constrain what roles can be granted.