PCSE Practice Question: Configuring Access Within a Cloud Solution Environment
An organization has a folder-level organization policy that enforces 'constraints/compute.requireShieldedVm'. A development team wants to create a test VM that does not use Shielded VM features. What is the correct approach?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Override the organization policy at the project level to set the constraint to 'not enforce' for that project.
Organization policies can be overridden at a lower level in the resource hierarchy using policy inheritance rules. The dev team should request an exemption for their project or folder by creating a policy override that sets the constraint to 'not enforce'. This must be done by a user with the appropriate organization policy administrator role.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create the VM in a different folder that does not have the policy.
Why it's wrong here
This might not be feasible if the project structure is fixed. The correct solution is to override the policy.
- ✗
Use a custom role that bypasses the organization policy.
Why it's wrong here
IAM roles cannot bypass organization policies. Policies are enforced regardless of roles.
- ✓
Override the organization policy at the project level to set the constraint to 'not enforce' for that project.
Why this is correct
Policy overrides at a lower level can change enforcement. The dev team should request an override.
- ✗
Create the VM with Shielded VM disabled; the policy will not apply to test projects.
Why it's wrong here
The policy at the folder level applies to all child projects. Attempting to create a VM without Shielded VM will fail.
Go deeper
Related to this question
About these practice questions
This PCSE question is part of Courseiva's 960-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCSE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCSE exam.