Google Associate Cloud EngineerSetting up a cloud solution environmentMedium

A large enterprise is setting up its Google Cloud environment and needs to enforce a policy that restricts all new resources, regardless of project, to be created only in the `us-central1` and `europe-west1` regions. This policy must apply to all future projects automatically and prevent users from overriding it. Which Google Cloud service should they use?

  1. AOrganization Policy Service.
  2. BCloud Security Command Center.
  3. CCloud IAM with custom roles.
  4. DResource Manager with labels.
Show answer & explanation

Correct answer: A. Organization Policy Service.

The Organization Policy Service is designed to centrally control resource usage across an entire Google Cloud organization. It allows administrators to define constraints, such as restricting resource locations, which are then enforced across all projects and folders within the organization and cannot be easily overridden by users.

Why the other options are wrong

  • B. Cloud Security Command Center is for security management and vulnerability detection, not for enforcing resource creation policies.
  • C. Cloud IAM manages who can do what, but not where resources can be created or specific resource properties.
  • D. Resource Manager labels are for organizing and filtering resources, not for enforcing policy constraints on their creation location.

Organization Policy Service

The Organization Policy Service allows Google Cloud administrators to programmatically control resources across their entire organization, enforcing constraints like allowed resource locations.

  • Applies policies at the Organization, Folder, or Project level.
  • Enforces constraints like `constraints/gcp.resourceLocations`.
  • Policies are inherited and can prevent non-compliant resource creation.

Memory trick: To organize and enforce policies across the organization, use the Organization Policy Service.

More Setting up a cloud solution environment questions