Google Associate Cloud EngineerSetting up a cloud solution environmentHard
A compliance officer needs to ensure that all Google Cloud Storage buckets created within the organization are uniformly configured with specific default encryption settings and lifecycle rules. They want to prevent individual project administrators from overriding these organizational standards for new buckets. How can this be enforced across the organization?
- AUse Cloud Deployment Manager templates for all bucket creation.
- BGrant 'Storage Object Creator' role with conditions to restrict bucket creation.
- CDevelop a Cloud Function that checks new buckets and applies correct settings.
- DApply an Organization Policy constraint to enforce Cloud Storage bucket policies.
Show answer & explanationAnswer & explanation
Correct answer: D. Apply an Organization Policy constraint to enforce Cloud Storage bucket policies.
Organization Policy Service can enforce constraints on Cloud Storage buckets, such as requiring specific default encryption (e.g., `constraints/gcp.restrictCmekCryptoKeys`) or preventing public access. While not directly enforcing lifecycle rules, it can enforce critical security and compliance settings for new buckets at an organizational level, preventing overrides.
Why the other options are wrong
- A. Deployment Manager templates can define compliant buckets, but they don't prevent users from creating non-compliant buckets manually or via other means.
- B. IAM roles manage permissions (who can do what), not resource configurations (how resources are configured). Conditions could restrict creation but not enforce specific bucket settings.
- C. A Cloud Function is reactive (after creation) and allows for non-compliant buckets to exist temporarily. It's a remediation, not a prevention mechanism.
Org Policy for Cloud Storage
Organization Policy Service can enforce mandatory configurations for Google Cloud Storage buckets, such as default encryption settings, across an entire organization.
- Uses constraints like `gcp.restrictCmekCryptoKeys`.
- Prevents creation of non-compliant buckets.
- Enforces organization-wide security and compliance standards.
Memory trick: Org Policy is the 'Boss' for 'Buckets' ensuring 'Compliance'.