Courseiva

Cloud Digital Leader How Google Cloud Resources Are Managed Practice Question

An organization needs to enforce that resources in a specific project cannot use certain machine series (e.g., f1-micro) due to performance requirements. They also need to tag resources with an 'environment' label for cost tracking. Which TWO methods should they use? (Choose TWO.)

⚠ Common exam trap

GCDL often tests the confusion between network tags (firewall/routing) and labels (metadata/billing), and between IAM deny policies (identity permissions) and org policies (resource configuration guardrails).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a label 'environment' to each resource for cost tracking

Option B is correct because labels are the standard Google Cloud mechanism for attaching key-value metadata such as 'environment' to resources, and labels are what feed into billing exports and cost breakdown reports for cost tracking. Option E is correct because an organization policy using the compute.disableMachineSeries constraint (a list constraint on compute.googleapis.com/Instance machine types) can be applied at the project or folder level to block creation of instances using the specified machine series like f1-micro, which directly enforces the performance requirement. Option A is incorrect because network tags are used for firewall rules and routing, not for restricting machine types or enforcing policy. Option C is incorrect because Cloud Audit Logs only provide visibility and post-hoc monitoring, not preventive enforcement. Option D is incorrect because IAM deny policies control who can perform actions based on permissions, not which machine series or resource configurations are allowed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use resource tags (network tags) to deny f1-micro usage

    Why it's wrong here

    Resource tags (network tags) are metadata strings attached to VM instances that are used exclusively by VPC firewall rules to select source or destination for applying allow/deny rules. They cannot be used to restrict the machine series or deny creation of an instance with a specific configuration. The correct mechanism for such enforcement is an organization policy constraint like `compute.disableMachineSeries`, not network tags.

  • ✓

    Add a label 'environment' to each resource for cost tracking

    Why this is correct

    Labels are key-value pairs that can be applied to all Google Cloud resources and are indexed by Cloud Billing for cost allocation and reporting. Adding an `environment` label to each resource allows the organization to break down costs by environment, ensuring accurate cost tracking and chargeback. This satisfies the requirement of enforcing cost tracking, which labels are specifically designed for.

  • ✗

    Use Cloud Audit Logs to monitor f1-micro usage and manually enforce

    Why it's wrong here

    Cloud Audit Logs capture administrative activity and data access events, providing a historical record for monitoring, auditing, and forensic investigation. However, they are a detective control: they can show that an f1-micro instance was created, but they cannot prevent its creation or automatically enforce policy. Relying on manual log review and manual remediation is inefficient, error-prone, and not a native enforcement mechanism.

  • ✗

    Apply a deny IAM policy to prevent creation of f1-micro instances

    Why it's wrong here

    IAM deny policies allow you to deny specific IAM permissions, such as `compute.instances.create`, but they cannot restrict the value of the `machineType` field in the create request. IAM conditions can restrict access based on resource attributes like name or tag, but not on machine series. Blocking a specific machine series requires an organizational policy constraint, not an IAM deny policy.

  • ✓

    Create an organization policy with a compute.disableMachineSeries constraint at the folder or project level

    Why this is correct

    The `compute.disableMachineSeries` organization policy constraint lets you explicitly deny one or more machine series, such as `f1-micro`, across a folder or project hierarchy. This constraint is enforced at resource creation time and is inherited by all child resources, providing a preventive control that blocks the creation of instances with the forbidden series. It can be configured with `denied_values` to list the machine series that are disallowed, making it the appropriate method for this requirement.

About these practice questions

Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.