Courseiva

Cloud Digital Leader Scaling with Google Cloud operations Practice Question

A company has a Google Cloud environment with 50 projects and 200 engineers. The security team wants to ensure that a new security policy — requiring all Cloud Storage buckets to have uniform bucket-level access enabled — applies to all existing and future buckets across all projects. Which approach scales to the entire organization?

⚠ Common exam trap

The GCDL exam often tests the distinction between reactive remediation (e.g., Cloud Functions) and proactive enforcement (e.g., Organization Policies), where candidates may choose a technically functional but less scalable or secure option like C because it seems automated, missing the requirement for organization-wide, preventive enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply an Organization Policy constraint ('storage.uniformBucketLevelAccess') at the organization level to enforce the setting automatically across all current and future projects and buckets

Organization Policy constraints, such as `storage.uniformBucketLevelAccess`, are enforced at the organization level and automatically apply to all existing and future projects and resources within the organization. This ensures uniform compliance without manual intervention, scaling seamlessly across 50 projects and 200 engineers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Send an email to all 200 engineers explaining the policy and asking them to manually enable uniform bucket-level access on their buckets

    Why it's wrong here

    Relying on an email to 200 engineers is a manual, advisory control with no technical enforcement: there is no way to verify who read the email, who correctly applied the setting, or which buckets were missed. It also does not scale to future projects or new buckets created after the email is sent, because each new bucket would again depend on the engineer remembering the instruction. Even if every engineer complies, the process is error-prone and completely unverified, leaving the organization without an auditable, automated assurance of compliance. Organization Policy removes individual human action from the equation, making the constraint uniformly applied across all projects regardless of engineer behavior.

  • ✓

    Apply an Organization Policy constraint ('storage.uniformBucketLevelAccess') at the organization level to enforce the setting automatically across all current and future projects and buckets

    Why this is correct

    Organization Policy is the scalable solution. By applying the constraint at the organization level, it cascades to all 50 projects automatically. New projects created in the future also inherit the constraint. No per-project configuration or per-engineer action required.

  • ✗

    Create a Cloud Function that checks bucket configurations hourly and enables uniform access on non-compliant buckets

    Why it's wrong here

    An hourly Cloud Function remediation is a reactive, event-consistency mechanism: between the moment a non-compliant bucket is created and the next function invocation, the bucket remains publicly accessible per user intent, violating the security baseline. It also requires managing Cloud Scheduler, function code, and error handling, and it may fail silently if the function's service account lacks sufficient permissions. In contrast, an Organization Policy constraint is evaluated synchronously at resource creation time, so a non-compliant bucket is rejected before it ever exists. The function approach adds operational complexity and a compliance gap, whereas the policy provides deterministic, upfront enforcement.

  • ✗

    Grant the security team Owner access to all 50 projects so they can manually enforce the policy in each project

    Why it's wrong here

    Granting Owner access to 50 projects for manual configuration work is an operational anti-pattern — it doesn't scale, creates security risk (overly broad access), and leaves enforcement dependent on manual work that can be forgotten or skipped.

About these practice questions

Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.