Cloud Digital Leader Google Cloud Security Practice Question
An organization has a compliance requirement to run workloads in specific geographic regions only. They want to prevent any resources from being created outside those regions. Which Google Cloud control should they use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Organization policy with location restriction
Organization policies with location restrictions allow administrators to set constraints on where resources can be created. The constraint `gcp.resourceLocations` can be used to restrict allowed regions. IAM roles control who can create resources, but not where. VPC Service Controls restrict data access, not resource creation location. Cloud Audit Logs only record actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Audit Logs
Why it's wrong here
Cloud Audit Logs are an observability and auditing mechanism that records actions performed in Google Cloud, such as who created a resource, when, and from where. They are entirely passive: they capture a trail of events for security and compliance review, but they do not evaluate or block any request based on region. Because audit logs cannot enforce restrictions or reject a resource creation request in a disallowed location, they do not satisfy a workload running in a required geographic area.
- ✓
Organization policy with location restriction
Why this is correct
The organization policy constraint `gcp.resourceLocations` is the correct mechanism because it actively enforces geographic compliance at resource creation time. By defining an allowlist of permitted locations at the organization, folder, or project level, Google Cloud blocks any attempt to create a resource outside those regions. This is a centralized, context-aware enforcement that works across supported services, making it the native, authoritative way to guarantee workloads run only in mandated locations.
- ✗
VPC Service Controls
Why it's wrong here
VPC Service Controls create security perimeters that regulate data movement to and from supported Google Cloud services, primarily to prevent exfiltration of sensitive data. They do not restrict where resources are physically or virtually created; a resource can still be provisioned in any region permitted by other policies. While perimeters can be configured for specific regions, that is an artifact of resource location rather than a boundary that enforces location compliance, so VPC SC alone cannot ensure a workload runs solely in approved locations.
- ✗
IAM conditions with resource location
Why it's wrong here
IAM conditions allow fine-grained access control based on attributes like `resource.location`, so you can limit a principal's permissions to act on resources that already exist in certain regions. However, they are not a global enforcement mechanism for resource placement: they must be attached to specific roles and principals, and they are only supported for a limited set of services and operations. For create operations, the condition may not be evaluated consistently, and it doesn't prevent other authorized principals or automated services from creating resources in disallowed regions. Thus, IAM conditions cannot provide a reliable, org-wide restriction on where workloads are deployed.
Go deeper
Related to this question
Learn chapter
Data Sovereignty and Compliance on Google Cloud
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Cloud Audit Logs
Cloud Audit Logs are a record of actions taken by users, services, and resources inside a cloud environment, capturing who did what, when, and from where.
About these practice questions
Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.