Courseiva
How Google Cloud Resources Are ManagedmediumMultiple ChoiceObjective-mapped

Cloud Digital Leader How Google Cloud Resources Are Managed Practice Question

A company has a folder for each department. The Finance team needs to prevent all projects under its folder from creating external IP addresses. What is the most efficient way to enforce this restriction?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Apply an organization policy constraint at the folder level

Organization policies can be defined at any level of the resource hierarchy and are inherited by child resources. Setting a constraint at the folder level applies to all projects under that folder.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure a service perimeter in VPC Service Controls

    Why it's wrong here

    VPC Service Controls establishes security perimeters around Google-managed APIs such as BigQuery, Cloud Storage, and Pub/Sub to prevent data exfiltration by untrusted networks. It does not intercept Compute Engine resource creation calls, so a VM can still be created with an external IP address; the perimeter would only restrict API access after the resource exists.

  • Use a deny IAM policy at the folder level

    Why it's wrong here

    An IAM deny policy, like an allow policy, authorizes or refuses actions based on principals and permissions, but it cannot condition on resource attributes such as the presence of an external IP. To block external IP creation you would need to deny the compute.instances.create permission entirely, which would halt all VM creation across the folder instead of just preventing external IP addresses.

  • Apply an organization policy constraint at the folder level

    Why this is correct

    The correct answer is to apply an organization policy constraint such as constraints/compute.vmExternalIpAccess at the folder level. This list constraint denies or permits the assignment of external IP addresses to VM instances, and because organization policies are hierarchical, the folder-level setting is inherited by every project and resource within that folder, enforcing the guardrail centrally.

  • Set a VPC firewall rule in each project

    Why it's wrong here

    VPC firewall rules are stateful packet filters that evaluate traffic at the network interface level, allowing or denying connections based on source/destination IP, port, and protocol. They are never consulted during the resource creation workflow, so a VM can still receive an ephemeral or static external IP even if inbound internet traffic is entirely blocked.

About these practice questions

Courseiva writes every GCDL question from scratch — 829 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.