A platform team must provision hundreds of projects with consistent IAM, networking, logging, and labels, repeatably and reviewably. Which approach fits BEST?
Professional Cloud DevOps Engineer
GCP_PCDEReady to test yourself?
A timed, blueprint-proportional exam drawn fresh from this bank โ with a per-domain score report.
๐ Free preview: showing 10 of 50 questions. Unlock the full bank โ every question, explanation, and reference.
Unlock all 50 questions โ10 questions across 5 topics. Choose an answer for each question, then check it to see the correct answer and explanation.
Filter by topic
9 questions in Bootstrapping a Google Cloud organization for DevOps
Bootstrapping a Google Cloud organization for DevOps
9 questions in topicResource hierarchy, IAM, Infrastructure as Code, org policies, and landing zones.
Security must enforce org-wide guardrails (no external IPs, restricted locations, no service-account key creation) regardless of project owners' IAM. Which mechanism fits?
A company wants IAM and org policies applied once and inherited by 40 projects owned by one team. What should they use?
Following least privilege in production, how should access be granted to engineers with the least ongoing maintenance?
A GKE workload needs Google API access following best practice with no long-lived keys. What should be configured?
During a Sev-1 incident, an on-call engineer occasionally needs elevated access they don't normally hold. What is the recommended pattern?
To limit blast radius and apply different access/policies, how should dev, staging, and prod be separated?
Security wants all organization logs routed to one destination for retention and SIEM analysis. Which feature should be used?
Which two are best practices when bootstrapping a Google Cloud organization for DevOps? (Choose two.)