Google Associate Cloud EngineerSetting up a cloud solution environmentHard
A company is implementing a new policy to restrict the geographic locations where resources can be created. They want to ensure that all new virtual machines and storage buckets are only deployed in the 'us-central1' or 'us-east1' regions, and specifically prevent deployment in any Asian regions. Which Google Cloud service and configuration would best enforce this policy organization-wide?
- ACloud Monitoring alerts for resource creation in unauthorized regions.
- BCloud IAM with custom roles denying access to Asian regions.
- COrganization Policy Service with a 'Resource Location Restriction' constraint.
- DVPC Service Controls to define service perimeters around allowed regions.
Show answer & explanationAnswer & explanation
Correct answer: C. Organization Policy Service with a 'Resource Location Restriction' constraint.
The Organization Policy Service, specifically with the `constraints/gcp.resourceLocations` (Resource Location Restriction) constraint, is designed to enforce policies across an entire organization or folders, limiting where new resources can be deployed based on location.
Why the other options are wrong
- A. Cloud Monitoring can *alert* after a resource is created, but it doesn't *prevent* the creation in the first place.
- B. IAM roles manage *who* can do *what*, not *where* resources can be created globally.
- D. VPC Service Controls create security perimeters to prevent data exfiltration, not to restrict the geographic deployment of new resources themselves.
Organization Policy Service (Resource Location)
The Google Cloud Organization Policy Service allows administrators to define constraints across their resource hierarchy, including restricting resource deployment to specific geographic locations.
- Applies to Organization, Folder, or Project levels.
- Uses `constraints/gcp.resourceLocations`.
- Prevents resource creation in disallowed regions/zones.
Memory trick: For company-wide rules, use the Organization's policy scroll.