Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is establishing a multi-tier Google Cloud resource hierarchy to support several business units with strict regulatory requirements across Development, Staging, and Production environments. The security architecture must satisfy the following constraints:
Which resource hierarchy and access governance architecture should the organization deploy?
An environment-first multi-level folder structure places top-level folders according to lifecycle stages (such as Production and Non-Production) beneath the root Organization node, with departmental or business unit folders nested underneath. Project provisioning and Cloud Billing attachments are strictly governed via a centralized automation pipeline using dedicated service accounts, while network infrastructure is decoupled using Shared VPC.
Production folder level without impacting Development flexibility.roles/compute.networkUser role on designated subnets within their assigned service projects.roles/resourcemanager.projectCreator and roles/billing.user to automated deployment service accounts eliminates unauthorized project creation, enforces standard naming conventions, and prevents shadow IT.This approach strikes the optimal balance between centralized governance (automated project provisioning, security policies, and network management) and developer agility (autonomous resource deployment within sandboxed service projects).
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.