Google PCA Design for security and compliance Practice Question
An organization has a security policy that prohibits the use of external IP addresses on Compute Engine instances to reduce attack surface. They want to enforce this policy across all new and existing projects. Which approach should they use?
⚠ Common exam trap
Many exam-takers confuse IAM conditions (which control who can perform an action) with Organization Policy constraints (which control what actions are allowed), leading them to choose IAM conditions as a preventive control when they only provide authorization-level restrictions, not resource-level enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Organization Policy with constraint compute.vmExternalIpAccess
The Organization Policy constraint `compute.vmExternalIpAccess` is the correct approach because it allows you to set a policy at the organization, folder, or project level that denies the assignment of external IP addresses to Compute Engine instances. This policy is enforced at resource creation time and applies to all new and existing VM instances, ensuring compliance with the security policy across the entire resource hierarchy. It directly prevents the use of external IPs, reducing the attack surface without requiring per-project or per-instance configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Organization Policy with constraint compute.vmExternalIpAccess
Why this is correct
The `compute.vmExternalIpAccess` organisation policy constraint directly enforces the no-external-IP requirement across every project in the organisation, denying instance creation or update when an external address is attached. Unlike per-project firewall rules or IAM controls, it applies hierarchically at the organisation node, satisfying the mandate for both new and existing projects.
- ✗
Use IAM conditions to prevent creation of instances with external IPs
Why it's wrong here
IAM conditions cannot evaluate whether a Compute Engine instance requests an external IP; they gate permissions on resource attributes and request context, not instance network configuration. It is tempting because IAM conditions do restrict API calls, and they would be correct for limiting who may create instances in specific projects, but they cannot inspect the external IP field itself.
- ✗
Use Cloud Security Command Center to detect and alert on external IPs
Why it's wrong here
Security Command Center detects and alerts on existing external IP findings but does not block creation, so it cannot enforce the policy. It is tempting because SCC provides org-wide visibility and would be correct for auditing or reporting external IP exposure across projects, yet the requirement is prevention, not detection.
- ✗
Use VPC Firewall rules to block traffic to external IPs
Why it's wrong here
VPC firewall rules filter traffic to and from instances but do not remove or prevent an external IP address from being assigned; the instance still holds the address and remains reachable via that path. It is tempting because firewalls control network access, and they would be correct for restricting which ports or sources may reach a VM, but not for preventing address assignment.
Go deeper
Related to this question
Learn chapter
Virtual Machine Instances in Compute Engine
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Project
A project is a temporary endeavor with a defined beginning and end, undertaken to create a unique product, service, or result, managed through specific processes in IT environments.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.