professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial services organization is architecting its Google Cloud environment to support automated data pipelines and analytics workloads. The company has distinct compliance requirements across its environments and needs to design a resource hierarchy that enforces strict data governance.
The architecture must satisfy the following requirements:
How should the organization structure its resource hierarchy and security boundaries?
Create separate standalone Google Cloud organizations for development and production; configure folder-level aggregated sinks in each; and attach standard Cloud Armor security policies to Cloud Storage buckets.
Organize projects into top-level environment folders (such as Development and Production); enforce Organization Policy constraints and aggregated Cloud Logging sinks at the folder level; and place production data projects inside a VPC Service Controls security perimeter.
Place all development and production projects directly under the Organization node; configure ConsumerPolicy resources via Service Usage on each project; and use Hierarchical Firewall Policies to restrict BigQuery API calls.
Group projects by individual business unit folders; manage individual Cloud Logging sinks inside each data project; and apply IAM Deny policies on BigQuery datasets to restrict network egress.
Create separate standalone Google Cloud organizations for development and production; configure folder-level aggregated sinks in each; and attach standard Cloud Armor security policies to Cloud Storage buckets.
Organize projects into top-level environment folders (such as Development and Production); enforce Organization Policy constraints and aggregated Cloud Logging sinks at the folder level; and place production data projects inside a VPC Service Controls security perimeter.
This architecture establishes a multi-tiered resource hierarchy structured around application environments (Development, Production) directly under the Organization node. It leverages folder-level inheritance to enforce Organization Policy constraints and aggregated Cloud Logging sinks, while isolating production data services within a VPC Service Controls (VPC SC) perimeter.
Production folder level. These policies are inherited across all child projects hosting production workloads, while the Development folder can maintain more permissive configurations.Designing the top-level folders by application environment aligns directly with centralized security governance needs where production requirements strictly diverge from non-production requirements. Combining folder inheritance with VPC Service Controls delivers defense-in-depth against both internal misconfigurations and external exfiltration.
Place all development and production projects directly under the Organization node; configure ConsumerPolicy resources via Service Usage on each project; and use Hierarchical Firewall Policies to restrict BigQuery API calls.
Group projects by individual business unit folders; manage individual Cloud Logging sinks inside each data project; and apply IAM Deny policies on BigQuery datasets to restrict network egress.