ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 171 - Professional Cloud Security Engineer discussion

Report
Export

You have created an OS image that is hardened per your organization's security standards and is being stored in a project managed by the security team. As a Google Cloud administrator, you need to make sure all VMs in your Google Cloud organization can only use that specific OS image while minimizing operational overhead. What should you do? (Choose two.)

A.
Grant users the compuce.imageUser role in their own projects.
Answers
A.
Grant users the compuce.imageUser role in their own projects.
B.
Grant users the compuce.imageUser role in the OS image project.
Answers
B.
Grant users the compuce.imageUser role in the OS image project.
C.
Store the image in every project that is spun up in your organization.
Answers
C.
Store the image in every project that is spun up in your organization.
D.
Set up an image access organization policy constraint, and list the security team managed project in the projects allow list.
Answers
D.
Set up an image access organization policy constraint, and list the security team managed project in the projects allow list.
E.
Remove VM instance creation permission from users of the projects, and only allow you and your team to create VM instances.
Answers
E.
Remove VM instance creation permission from users of the projects, and only allow you and your team to create VM instances.
Suggested answer: B, D

Explanation:

https://cloud.google.com/resource-manager/docs/organization-policy/org-policy-constraints - constraints/compute.trustedImageProjects

This list constraint defines the set of projects that can be used for image storage and disk instantiation for Compute Engine. If this constraint is active, only images from trusted projects will be allowed as the source for boot disks for new instances.

asked 18/09/2024
Alexandru adrian Blaga
22 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first