ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 127 - Professional Cloud Security Engineer discussion

Report
Export

You want to prevent users from accidentally deleting a Shared VPC host project. Which organization-level policy constraint should you enable?

A.
compute.restrictSharedVpcHostProjects
Answers
A.
compute.restrictSharedVpcHostProjects
B.
compute.restrictXpnProjectLienRemoval
Answers
B.
compute.restrictXpnProjectLienRemoval
C.
compute.restrictSharedVpcSubnetworks
Answers
C.
compute.restrictSharedVpcSubnetworks
D.
compute.sharedReservationsOwnerProjects
Answers
D.
compute.sharedReservationsOwnerProjects
Suggested answer: B

Explanation:

https://cloud.google.com/resource-manager/docs/organization-policy/org-policy-constraints#constraints-for-specific-services

- constraints/compute.restrictXpnProjectLienRemoval

- Restrict shared VPC project lien removal

This boolean constraint restricts the set of users that can remove a Shared VPC host project lien without organization-level permission where this constraint is set to True.

By default, any user with the permission to update liens can remove a Shared VPC host project lien. Enforcing this constraint requires that permission be granted at the organization level.

asked 18/09/2024
trobbies Real
26 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first