Professional Cloud ArchitectDesign for security and complianceHard
A large enterprise is migrating its legacy applications to Google Cloud. They have a strict policy that all virtual machines and associated resources must be deployed with specific security configurations, such as disabling external IP addresses, enabling OS Login, and ensuring specific network tags are applied. Manually enforcing these configurations across hundreds of projects and thousands of resources is error-prone. Which Google Cloud service can be used to programmatically define and enforce these security and compliance configurations across the organization?
- AResource Manager
- BOrganization Policy Service
- CIAM Conditions
- DCloud Deployment Manager
Show answer & explanationAnswer & explanation
Correct answer: B. Organization Policy Service
Organization Policy Service allows administrators to programmatically define granular constraints on how Google Cloud resources can be configured and deployed across an organization, enforcing compliance and security policies at scale.
Why the other options are wrong
- A. Resource Manager manages the resource hierarchy (organizations, folders, projects) but doesn't, by itself, define or enforce policies on resource configurations; Organization Policy Service does that.
- C. IAM Conditions add conditional logic to IAM policies (e.g., time-based access), but they don't enforce resource configuration settings.
- D. Cloud Deployment Manager automates resource deployment (Infrastructure as Code) but doesn't enforce ongoing organizational policies or prevent manual overrides.
Google Cloud Organization Policy Service
A service that allows organizations to programmatically define and enforce constraints on the configuration of Google Cloud resources across the entire organization, folders, or projects.
- Part of Resource Manager, applies constraints to resource creation/updates.
- Helps enforce security, compliance, and cost management policies.
- Examples: restrict external IP usage, define allowed regions, enforce CMEK.
Memory trick: Organization Policies Orchestrate Order.