Courseiva
How Google Cloud Resources Are ManagedmediumMultiple ChoiceObjective-mapped

Cloud Digital Leader How Google Cloud Resources Are Managed Practice Question

A company wants to enforce a policy that prevents all projects in the organization from enabling certain Google Cloud APIs. Where should the policy be applied to ensure it is inherited by all projects, including future ones?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

On the organization node

Organization policies applied at the organization node are inherited by all folders and projects under it. This is the most efficient way to enforce a blanket restriction across the entire resource hierarchy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • On the organization node

    Why this is correct

    The organization node is the root of the Google Cloud resource hierarchy. Organization policies set at this level are inherited by every folder and project beneath it, including future projects that are created later. This is the only placement that guarantees the policy is enforced uniformly across all projects in the organization without any per-project or per-folder exceptions.

  • On the billing account

    Why it's wrong here

    Billing accounts are not part of the resource hierarchy and cannot have organization policies attached. They serve solely for cost management, payments, and linking projects for billing purposes. Google Cloud does not support placing API enablement restrictions or other resource constraints on a billing account, so this approach is technically impossible.

  • On each individual project

    Why it's wrong here

    Applying the policy to each individual project would require repeated manual configuration for every existing project, and any new project created after the policy is set would miss it unless someone remembers to apply it again. This approach is inefficient, error-prone, and does not scale across a large organization. Even if every current project is covered, future projects are not automatically protected, leaving compliance gaps.

  • On the folder containing the projects

    Why it's wrong here

    A folder-level policy only affects the projects contained in that specific folder branch of the hierarchy. Projects located in other folders, or directly under the organization node, would remain outside the policy scope. Therefore, this placement does not meet the requirement of covering all projects—only the organization node provides the necessary global breadth.

About these practice questions

One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.