Your company must follow industry specific regulations. Therefore, you need to enforce customer-managed encryption keys (CMEK) for all new Cloud Storage resources in the organization called org1.
What command should you execute?
A.
• organization poli-cy:constraints/gcp.restrictStorageNonCmekServices • binding at: org1 • policy type: allow • policy value: all supported services
Require CMEK protection
To require CMEK protection for your organization, configure the constraints/gcp.restrictNonCmekServices organization policy.
As a list constraint, the accepted values for this constraint are Google Cloud service names (for example, bigquery.googleapis.com). Use this constraint by providing a list of Google Cloud service names and setting the constraint to Deny. This configuration blocks the creation of resources in these services if the resource is not protected by CMEK. In other words, requests to create a resource in the service don't succeed without specifying a Cloud KMS key.
https://cloud.google.com/kms/docs/cmek-org-policy#require-cmek
I cannot found the so called "restrictStorageNonCmekServices" in Google document
Policy Name: constraints/gcp.restrictNonCmekServices:
This policy ensures that resources in specified Google Cloud services (e.g., Cloud Storage) cannot be created without enabling CMEK.
It also prevents the removal of CMEK from existing resources.
D is the correct:
Use this constraint by configuring a list of resource hierarchy indicators and setting the constraint to Allow.
https://cloud.google.com/kms/docs/cmek-org-policy#project-constraint
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
KLei
4 months, 1 week agoBPzen
4 months, 4 weeks agorottzy
1 year, 7 months agocyberpunk21
1 year, 8 months agoanshad666
1 year, 8 months agoMithung30
1 year, 8 months agopfilourenco
1 year, 8 months agoMithung30
1 year, 8 months agopfilourenco
1 year, 8 months agopfilourenco
1 year, 8 months agoa190d62
1 year, 8 months ago