Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is establishing a multi-tier Google Cloud resource hierarchy to support several business units with strict regulatory requirements across Development, Staging, and Production environments. The security architecture must satisfy the following constraints:
Which resource hierarchy and access governance architecture should the organization deploy?
Deploy a decentralized hierarchy where each business unit folder is granted the Folder Admin role, permit each team to create standalone VPC networks per project connected via VPC Network Peering across environments, and synchronize domain local Active Directory security groups via a single GCDS instance.
Organize top-level folders by business unit, place development and production projects within the same business unit folder, deploy a single global Shared VPC host project for all environments, and grant application team leads the Project Creator and Billing User roles at the root Organization node.
Organize top-level folders by environment (Production, Non-Production), nest business unit subfolders within each environment, deploy environment-specific Shared VPC host projects managed by a central network team, restrict project creation and billing linkage to an automated provisioning service account, and grant developers subnet-level network user permissions in their service projects.
Create a single flat folder structure under the Organization node, deploy domain controllers inside each application project, assign the Billing Account Administrator role to development leads, and rely on project-level IAM policies without inherited folder constraints.
Deploy a decentralized hierarchy where each business unit folder is granted the Folder Admin role, permit each team to create standalone VPC networks per project connected via VPC Network Peering across environments, and synchronize domain local Active Directory security groups via a single GCDS instance.
Organize top-level folders by business unit, place development and production projects within the same business unit folder, deploy a single global Shared VPC host project for all environments, and grant application team leads the Project Creator and Billing User roles at the root Organization node.
Organize top-level folders by environment (Production, Non-Production), nest business unit subfolders within each environment, deploy environment-specific Shared VPC host projects managed by a central network team, restrict project creation and billing linkage to an automated provisioning service account, and grant developers subnet-level network user permissions in their service projects.
An environment-first multi-level folder structure places top-level folders according to lifecycle stages (such as Production and Non-Production) beneath the root Organization node, with departmental or business unit folders nested underneath. Project provisioning and Cloud Billing attachments are strictly governed via a centralized automation pipeline using dedicated service accounts, while network infrastructure is decoupled using Shared VPC.
Production folder level without impacting Development flexibility.roles/compute.networkUser role on designated subnets within their assigned service projects.roles/resourcemanager.projectCreator and roles/billing.user to automated deployment service accounts eliminates unauthorized project creation, enforces standard naming conventions, and prevents shadow IT.This approach strikes the optimal balance between centralized governance (automated project provisioning, security policies, and network management) and developer agility (autonomous resource deployment within sandboxed service projects).
Create a single flat folder structure under the Organization node, deploy domain controllers inside each application project, assign the Billing Account Administrator role to development leads, and rely on project-level IAM policies without inherited folder constraints.