Courseiva

PCSE Practice Question: Configuring Access Within a Cloud Solution Environment

An organization has a folder-level organization policy that enforces 'constraints/compute.requireShieldedVm'. A development team wants to create a test VM that does not use Shielded VM features. What is the correct approach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Override the organization policy at the project level to set the constraint to 'not enforce' for that project.

Organization policies can be overridden at a lower level in the resource hierarchy using policy inheritance rules. The dev team should request an exemption for their project or folder by creating a policy override that sets the constraint to 'not enforce'. This must be done by a user with the appropriate organization policy administrator role.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create the VM in a different folder that does not have the policy.

    Why it's wrong here

    This might not be feasible if the project structure is fixed. The correct solution is to override the policy.

  • Use a custom role that bypasses the organization policy.

    Why it's wrong here

    IAM roles cannot bypass organization policies. Policies are enforced regardless of roles.

  • Override the organization policy at the project level to set the constraint to 'not enforce' for that project.

    Why this is correct

    Policy overrides at a lower level can change enforcement. The dev team should request an override.

  • Create the VM with Shielded VM disabled; the policy will not apply to test projects.

    Why it's wrong here

    The policy at the folder level applies to all child projects. Attempting to create a VM without Shielded VM will fail.

About these practice questions

This PCSE question is part of Courseiva's 960-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCSE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCSE exam.