Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam Professional Cloud Security Engineer topic 1 question 133 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 133
Topic #: 1
[All Professional Cloud Security Engineer Questions]

Your company's Chief Information Security Officer (CISO) creates a requirement that business data must be stored in specific locations due to regulatory requirements that affect the company's global expansion plans. After working on the details to implement this requirement, you determine the following:
✑ The services in scope are included in the Google Cloud Data Residency Terms.
✑ The business data remains within specific locations under the same organization.
✑ The folder structure can contain multiple data residency locations.
You plan to use the Resource Location Restriction organization policy constraint. At which level in the resource hierarchy should you set the constraint?

  • A. Folder
  • B. Resource
  • C. Project
  • D. Organization
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
mouchu
Highly Voted 2 years ago
Answer = C "The folder structure can contain multiple data residency locations" suggest that restriction should be applied on projects level
upvoted 22 times
piyush_1982
1 year, 9 months ago
why not D?
upvoted 2 times
...
AzureDP900
1 year, 6 months ago
Yes, It is C. This is very tricky question and we need to read very carefully. In general Folders will used but in this case Project is right
upvoted 3 times
AzureDP900
1 year, 6 months ago
Q 137 is same
upvoted 1 times
...
...
...
Taliesyn
Highly Voted 2 years ago
Selected Answer: A
Org policies can't be applied on resources ...
upvoted 6 times
...
MFay
Most Recent 2 weeks, 3 days ago
Since you need to ensure that business data remains within specific locations under the same organization and the folder structure can contain multiple data residency locations, you should set the Resource Location Restriction organization policy constraint at the Organization level. Therefore, the correct answer is: D. Organization
upvoted 1 times
...
Bettoxicity
1 month, 2 weeks ago
Selected Answer: A
A Why not C?: Project-level constraints wouldn't offer the desired level of granularity. You might have data in a single project that needs to be stored in different locations based on regulations. Why no D?: Organization: An organization-level constraint would restrict all resources within the organization to a single residency location, which wouldn't meet the need for differentiated locations for various data sets.
upvoted 1 times
...
dija123
1 month, 3 weeks ago
Selected Answer: C
Agree with C
upvoted 1 times
...
desertlotus1211
8 months, 2 weeks ago
https://cloud.google.com/assured-workloads/docs/data-residency#:~:text=Organizations%20with%20data%20residency%20requirements,select%20your%20desired%20compliance%20program. Organizations with data residency requirements can set up a Resource Locations policy that constrains the location of new in-scope resources for their whole organization or for individual projects. Answer C is a better choice, though this documenttalks about folders. But the questions says there are multiple data residency locations in that folders, so project level seems to be the best.
upvoted 2 times
...
[Removed]
9 months, 4 weeks ago
Selected Answer: C
These restrictions can be applied at Org level, Folder Level or Project Level, but not resource level. Also, these policies are inherited, which means they need to be applied at the lowest child possible in the hierarchy where this is needed, not higher. This makes the answer specific to the use case rather than textbook knowledge. According to the given: "The folder structure can contain multiple data residency locations". This means that applying location restrictions at the Folder level or above will violate the requirement.This means you must apply the constraint at Project level. Quotes from the references below: "You can also apply the organization policy to a folder or a project with the folder or the project flags, and the folder ID and project ID, respectively." - no mention of resource level References: https://cloud.google.com/resource-manager/docs/organization-policy/understanding-hierarchy https://cloud.google.com/resource-manager/docs/organization-policy/using-constraints
upvoted 4 times
...
[Removed]
9 months, 4 weeks ago
"C" Project Level These restrictions can be applied at Org level, Folder Level or Project Level, but not resource level. Also, these policies are inherited, which means they need to be applied at the lowest child possible in the hierarchy where this is needed, not higher. This makes the answer specific to the use case rather than textbook knowledge. According to the given: "The folder structure can contain multiple data residency locations". This means that applying location restrictions at the Folder level or above will violate the requirement.This means you must apply the constraint at Project level. Quotes from the references below: "You can also apply the organization policy to a folder or a project with the folder or the project flags, and the folder ID and project ID, respectively." - no mention of resource level References: https://cloud.google.com/resource-manager/docs/organization-policy/understanding-hierarchy https://cloud.google.com/resource-manager/docs/organization-policy/using-constraints
upvoted 2 times
...
gcpengineer
1 year ago
Selected Answer: C
C is the ans
upvoted 3 times
...
AnishAd
1 year, 1 month ago
C it is ----> Imp line to read from Question to understand why At Project level : 1. business data must be stored in specific locations due to regulatory requirements & The folder structure can contain multiple data residency locations. --- > Since Folder is going to contain multiple data residency locations and requirement is to restrict in specific location , so Constraints should be set at project level.
upvoted 2 times
...
alleinallein
1 year, 1 month ago
Selected Answer: C
Project level seems to be reasonable.
upvoted 2 times
...
marrechea
1 year, 1 month ago
Selected Answer: C
As "The folder structure can contain multiple data residency locations." it has to be at project level
upvoted 2 times
...
fad3r
1 year, 1 month ago
A lot of madness in these answers. It is C. You cant apply it at the org level since that effects everything. You cant apply it at the folder level since can contain locations. You CAN apply it at the project level. For those who say you cant apply these policies at the org level I suggest you spend more time reading docs and testing things in a lab. https://cloud.google.com/blog/products/identity-security/meet-data-residency-requirements-with-google-cloud To strengthen these controls further, Google Cloud offers Organization Policy constraints which can be applied at the organization, folder, or project level
upvoted 2 times
...
adelynllllllllll
1 year, 5 months ago
the answer should be B https://cloud.google.com/resource-manager/docs/organization-policy/defining-locations
upvoted 1 times
...
Rightsaidfred
1 year, 5 months ago
Selected Answer: C
Different Locations therefore needs to be applied at Project Level.
upvoted 4 times
...
TonytheTiger
1 year, 6 months ago
To set an organization policy including a resource locations constraint: https://cloud.google.com/resource-manager/docs/organization-policy/defining-locations
upvoted 1 times
...
AzureDP900
1 year, 6 months ago
C is right
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...