exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 127 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 127
Topic #: 1
[All Professional Cloud Security Engineer Questions]

You want to prevent users from accidentally deleting a Shared VPC host project. Which organization-level policy constraint should you enable?

  • A. compute.restrictSharedVpcHostProjects
  • B. compute.restrictXpnProjectLienRemoval
  • C. compute.restrictSharedVpcSubnetworks
  • D. compute.sharedReservationsOwnerProjects
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Tabayashi
Highly Voted 2 years ago
Answer is (B). This boolean constraint restricts the set of users that can remove a Shared VPC project lien without organization-level permission where this constraint is set to True. https://cloud.google.com/resource-manager/docs/organization-policy/org-policy-constraints
upvoted 10 times
...
zellck
Highly Voted 1 year, 7 months ago
Selected Answer: B
B is the answer. https://cloud.google.com/resource-manager/docs/organization-policy/org-policy-constraints#constraints-for-specific-services - constraints/compute.restrictXpnProjectLienRemoval - Restrict shared VPC project lien removal This boolean constraint restricts the set of users that can remove a Shared VPC host project lien without organization-level permission where this constraint is set to True. By default, any user with the permission to update liens can remove a Shared VPC host project lien. Enforcing this constraint requires that permission be granted at the organization level.
upvoted 9 times
AzureDP900
1 year, 5 months ago
Agree with your explanation and Thank you for sharing the link
upvoted 2 times
...
...
Xoxoo
Most Recent 7 months, 1 week ago
Selected Answer: B
To prevent users from accidentally deleting a Shared VPC host project, you should enable the compute.restrictXpnProjectLienRemoval organization-level policy constraint . This policy constraint limits IAM principals who can remove the lien that prevents deletion of host projects . By default, a project owner can remove a lien from a project, including a Shared VPC host project, unless an organization-level policy is defined to limit lien removal . Therefore, option B is the correct answer.
upvoted 2 times
...
[Removed]
9 months, 1 week ago
Selected Answer: B
"B" GCP Shared VPC is formerly known as Google Cross-Project Networking (XPN) and still referred to as "XPN" in the API. References: https://cloud.google.com/vpc/docs/shared-vpc https://cloud.google.com/resource-manager/docs/organization-policy/org-policy-constraints#constraints-for-specific-services
upvoted 4 times
...
mikesp
1 year, 11 months ago
Selected Answer: B
https://cloud.google.com/resource-manager/docs/organization-policy/org-policy-constraints
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago