For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeGCP Professional Cloud ArchitectGCP Professional Cloud Architect Practice Exam 1Question 40
    Hard1 markMultiple Choice
    Subtask 1.1: Design a solution infrastructure that meets business requirementsGovernanceOrganization PolicySecurity

    GCP PCA · Question 40 · Design a solution infrastructure that meets business requirements

    Your enterprise has a strict policy that no public IP addresses can be assigned to Compute Engine instances, and all resources must be deployed in the europe-west1 region. How can you enforce these rules organization-wide? (Select TWO)

    Answer options:

    A.

    Apply an Organization Policy constraint to disable external IP addresses for Compute Engine.

    B.

    Create a VPC Firewall rule to block all outbound traffic to 0.0.0.0/0.

    C.

    Apply an Organization Policy constraint to restrict resource locations to europe-west1.

    D.

    Use IAM conditions to remove the compute.instances.create permission if the region is not europe-west1.

    E.

    Configure Cloud NAT to translate all public IPs to private IPs.

    How to approach this question

    Identify the GCP service used for centralized governance and guardrails.

    Full Answer

    The Organization Policy Service gives you centralized and programmatic control over your organization's cloud resources. It acts as a guardrail. Even if a user has the IAM permission to create a VM, an Organization Policy can block them from assigning a public IP or deploying it in an unauthorized region.

    Common mistakes

    Confusing IAM (who can do what) with Organization Policies (what can be done).
    Question 39All questionsQuestion 41

    Practice the full GCP Professional Cloud Architect Practice Exam 1

    50 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...HardQ02**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...MediumQ03**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...HardQ04**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...MediumQ05**CASE STUDY: TechStream Gaming** **Company Overview:** TechStream Gaming is a global gaming com...Medium
    View all 50 questions →