Google Associate Cloud EngineerSetting up a cloud solution environmentMedium

A solutions architect is designing a multi-project environment in Google Cloud. They need to ensure that all projects within a specific department (represented by a folder) inherit certain IAM policies and organizational constraints, such as disabling external IP addresses on VMs. Which level of the resource hierarchy should be used to apply these policies effectively?

  1. AOrganization Level
  2. BIndividual Project Level
  3. CFolder Level
  4. DResource Level (e.g., specific VM instance)
Show answer & explanation

Correct answer: C. Folder Level

The Folder level is specifically designed to group projects and apply common IAM policies and organizational constraints (like disabling external IPs) to all projects within that folder, ensuring inheritance and consistent governance.

Why the other options are wrong

  • A. Applying policies at the Organization level would affect *all* projects across the entire company, not just a specific department.
  • B. Applying policies at the individual project level is manual and doesn't ensure inheritance across the department.
  • D. Applying policies at the resource level is too granular and doesn't provide the desired inheritance for all projects in the department.

GCP Folder Hierarchy

Folders in Google Cloud provide an additional grouping mechanism for projects within an organization, allowing for the application of IAM policies and organizational policies that are inherited by contained projects.

  • Organizes projects into logical groups.
  • Enables policy inheritance from folders to projects.
  • Useful for departmental or environment segregation.

Memory trick: Policies flow down the tree, from organization to individual resources.

More Setting up a cloud solution environment questions