Google Associate Cloud EngineerSetting up a cloud solution environmentMedium
A security auditor needs to ensure that a Google Cloud project, which hosts critical production data, cannot be accidentally or maliciously deleted. The project should remain active indefinitely. What is the most effective and recommended way to prevent the deletion of this specific project?
- AEnable the Project Delete Lock feature on the project.
- BRemove all users from the 'Project Deleter' IAM role for that project.
- CSet a billing budget alert to notify if project deletion is attempted.
- DMove the project to a dedicated folder with restricted 'Project Deleter' permissions.
Show answer & explanationAnswer & explanation
Correct answer: A. Enable the Project Delete Lock feature on the project.
The Project Delete Lock feature is specifically designed to prevent accidental or malicious deletion of a project. When enabled, a project cannot be deleted until the lock is explicitly removed, overriding IAM permissions.
Why the other options are wrong
- B. While helpful, this is an IAM-based control. A user with an organization-level Project Deleter role could still delete it, or if permissions are misconfigured.
- C. A billing budget alert would only notify *after* an action, not prevent it. Deletion would likely happen before an alert is processed.
- D. Folder-level permissions are inherited, but a user with sufficient permissions at the organization level could still bypass this, or the folder itself could be deleted.
GCP Project Delete Lock
The Project Delete Lock is a feature that explicitly prevents a Google Cloud project from being deleted, providing an extra layer of protection against accidental or malicious project removal.
- Prevents project deletion until removed.
- Overrides most IAM permissions for deletion.
- Activated via `gcloud beta projects undelete set-policy`.
Memory trick: Lock your project to stop deletion, it's the strongest prevention.