Cloud Digital Leader Trust and security with Google Cloud Practice Question
Exhibit
Refer to the exhibit.
```
gcloud projects set-iam-policy my-project policy.yaml
```
policy.yaml:
```
{
"bindings": [
{
"role": "roles/compute.admin",
"members": [
"user:admin@example.com"
],
"condition": {
"title": "workstation_ip",
"expression": "request.host == '203.0.113.1'"
}
}
]
}
```Refer to the exhibit. A security engineer applies this IAM policy. What is the effect?
⚠ Common exam trap
Google Cloud exams may test the distinction between conditions on request attributes (e.g., `source.ip` for IP-based restrictions) and resource attributes (e.g., `resource.labels`). Candidates should recognize that IP-based restrictions use `source.ip`, not `resource.labels` or AWS-style keys like `aws:SourceIp`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access is allowed only from the IP address 203.0.113.1.
The IAM policy shown in the exhibit restricts access to requests coming from IP address 203.0.113.1. In Google Cloud IAM, this is expressed using a condition on `source.ip` (or `request.headers['x-goog-user-ip']`). Only requests from that IP satisfy the condition, and requests from any other IP are denied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Access is allowed only from the IP address 203.0.113.1.
Why this is correct
The IAM policy's condition is an IP-based restrictor: it declares that the principal's request is allowed only when the originating source IP address equals 203.0.113.1. Because this is the sole constraint in the condition (no resource, time, or authentication attributes are included), access is granted exclusively to requests coming from that exact address.
- ✗
Access is allowed only to resources tagged with 'production'.
Why it's wrong here
Resource tags, such as 'production', are represented in IAM conditions through attributes like `resource.labels` or `resource.name`. This policy's condition does not reference any `resource.*` attribute, so it cannot limit access to resources carrying a 'production' tag; it only restricts the caller's network location.
- ✗
Access is allowed only with two-factor authentication.
Why it's wrong here
Requiring two-factor authentication would be expressed with IAM condition attributes like `request.auth.claims` or `gcp.auth` (e.g., checking `request.auth.claims.nonexpiring` or `gcp.auth.level`). No such authentication-related attribute appears in the condition, so the policy cannot enforce MFA; it only checks the source IP address.
- ✗
Access is allowed only during business hours.
Why it's wrong here
Restricting access to business hours would require a temporal condition using `request.time` (or `resource.creation_time`), such as comparing the current time against a fixed window. Since this condition contains no `request.time` predicate, it does not limit access by time of day; the sole determining factor is the requester's IP address.
Go deeper
Related to this question
Learn chapter
Open Source and Open Standards at Google Cloud
Key term
Google Cloud
Google Cloud is a suite of cloud computing services offered by Google that provides infrastructure, platform, and software solutions over the internet.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.