New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Google Cloud Certified - Professional Cloud Security Engineer Professional-Cloud-Security-Engineer Question # 64 Topic 7 Discussion

Google Cloud Certified - Professional Cloud Security Engineer Professional-Cloud-Security-Engineer Question # 64 Topic 7 Discussion

Professional-Cloud-Security-Engineer Exam Topic 7 Question 64 Discussion:
Question #: 64
Topic #: 7

Your organization needs to restrict the types of Google Cloud services that can be deployed within specific folders to enforce compliance requirements. You must apply these restrictions only to the designated folders, without affecting other parts of the resource hierarchy. You want to use the most efficient and simple method. What should you do?


A.

Implement IAM conditions on service account creation within each folder.


B.

Create a global organization policy at the organization level with the Restrict Resource Service Usage constraint, and apply exceptions for other folders.


C.

Create an organization policy at the folder level using the Restrict Resource Service Usage constraint, and define the allowed services per folder.


D.

Configure VPC Service Controls perimeters around each folder, and define the allowed services within the perimeter.


Get Premium Professional-Cloud-Security-Engineer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.