Google Associate Cloud EngineerSetting up a cloud solution environmentHard
A security auditor needs to verify that a Google Cloud project is correctly configured to prevent accidental deletion of critical resources. They specifically want to ensure that the project itself cannot be deleted by unauthorized users or accidental actions. Which feature should be enabled at the project level?
- AProject Shutdown policy with a mandatory review workflow.
- BOrganization Policy Service with a 'disable-resource-deletion' constraint.
- CProject Lock (resource lock) to prevent deletion.
- DCloud IAM custom role with 'project.delete' permission denied.
Show answer & explanationAnswer & explanation
Correct answer: C. Project Lock (resource lock) to prevent deletion.
Project Lock (also known as Resource Lock or `gcloud projects add-iam-policy-binding` with `resource-manager.projects.delete` condition) is the most direct way to prevent accidental project deletion. While Organization Policies can enforce constraints, a Project Lock is specific to preventing deletion of that particular project.
Why the other options are wrong
- A. There isn't a native 'Project Shutdown policy with a mandatory review workflow' feature in GCP for this purpose.
- B. Organization Policy constraints can prevent project creation or enforce certain settings, but a direct 'disable-resource-deletion' constraint for projects themselves is not the primary mechanism to protect an *existing* project from deletion by authorized users.
- D. Denying a permission in a custom role only applies to users assigned that role; it doesn't prevent other users with broader permissions (like Owner) from deleting the project.
GCP Project Lock
A Project Lock (or Resource Lock) in Google Cloud is a mechanism to prevent accidental or malicious deletion of a project, even by users with the Project Owner role, until the lock is explicitly removed.
- Requires `resourcemanager.projects.update` permission to apply/remove.
- Protects against accidental deletion.
- Can be applied via gcloud CLI or API.
Memory trick: To stop deletion, put a lock on the project.