ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 129 - Professional Cloud Security Engineer discussion

Report
Export

You are a security administrator at your company. Per Google-recommended best practices, you implemented the domain restricted sharing organization policy to allow only required domains to access your projects. An engineering team is now reporting that users at an external partner outside your organization domain cannot be granted access to the resources in a project. How should you make an exception for your partner's domain while following the stated best practices?

A.
Turn off the domain restriction sharing organization policy. Set the policy value to 'Allow All.'
Answers
A.
Turn off the domain restriction sharing organization policy. Set the policy value to 'Allow All.'
B.
Turn off the domain restricted sharing organization policy. Provide the external partners with the required permissions using Google's Identity and Access Management (IAM) service.
Answers
B.
Turn off the domain restricted sharing organization policy. Provide the external partners with the required permissions using Google's Identity and Access Management (IAM) service.
C.
Turn off the domain restricted sharing organization policy. Add each partner's Google Workspace customer ID to a Google group, add the Google group as an exception under the organization policy, and then turn the policy back on.
Answers
C.
Turn off the domain restricted sharing organization policy. Add each partner's Google Workspace customer ID to a Google group, add the Google group as an exception under the organization policy, and then turn the policy back on.
D.
Turn off the domain restricted sharing organization policy. Set the policy value to 'Custom.' Add each external partner's Cloud Identity or Google Workspace customer ID as an exception under the organization policy, and then turn the policy back on.
Answers
D.
Turn off the domain restricted sharing organization policy. Set the policy value to 'Custom.' Add each external partner's Cloud Identity or Google Workspace customer ID as an exception under the organization policy, and then turn the policy back on.
Suggested answer: D

Explanation:

https://cloud.google.com/resource-manager/docs/organization-policy/restricting-domains#setting_the_organization_policy

The domain restriction constraint is a type of list constraint. Google Workspace customer IDs can be added and removed from the allowed_values list of a domain restriction constraint. The domain restriction constraint does not support denying values, and an organization policy can't be saved with IDs in the denied_values list. All domains associated with a Google Workspace account listed in the allowed_values will be allowed by the organization policy. All other domains will be denied by the organization policy.

asked 18/09/2024
MARCIA SHEILA PELAEZ GONZALEZ
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first