Courseiva

Cloud Digital Leader How Google Cloud Resources Are Managed Practice Question

An organization wants to ensure that all projects under a specific folder inherit a policy that disables the creation of external IP addresses. Which Google Cloud resource hierarchy level should the policy be applied to enforce this requirement for all child resources?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Folder

Organization policy constraints applied at the folder level are inherited by all projects and resources within that folder, ensuring consistent enforcement across the hierarchy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Folder

    Why this is correct

    Attaching the policy at the folder level is the most operative because IAM policies are inherited down the resource hierarchy. The folder acts as a container for all projects under it, so a policy bound at this level automatically applies to every project and resource within that subtree, including any future projects created in the folder. This provides consistent enforcement for the specific business unit or department without affecting unrelated folders or projects.

  • ✗

    Organization node

    Why it's wrong here

    Applying the policy at the organization node is the root of the resource hierarchy, so the policy would propagate to every folder, project, and resource in the entire organization. For a requirement scoped to only a specific folder’s projects, this over-broad application expands the policy’s effect far beyond the intended boundary, potentially breaking compliance or security expectations for independent departments. It also violates the principle of least privilege by granting or restricting access more widely than necessary.

  • ✗

    Resource (e.g., VM instance)

    Why it's wrong here

    A resource-level policy attachment, such as on a VM instance, affects only that single resource — it does not inherit up to other resources or down to related ones. To cover all projects in the folder, an administrator would need to attach the policy to each individual resource, which is impractical and almost certain to miss newly created resources. Because resource-level bindings lack inheritance, they cannot provide the uniform, folder-wide enforcement that the organization requires.

  • ✗

    Project

    Why it's wrong here

    Project-level policy application means every project in the folder would require a separate binding, making management manual and repetitive. If a new project is later added to the folder, it will not automatically receive the policy unless explicitly configured, leading to coverage gaps. Folder-level inheritance is more efficient and less error-prone because it establishes the policy once and propagates it to all current and future projects.

About these practice questions

Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.