Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Professional Cloud Security Engineer Exam - Topic 1 Question 123 Discussion

The CISO of your highly regulated organization has mandated that all AI applications running in production must be based on Google first-party models. Your security team has now implemented the Model Garden's organization policy meant to centrally control access and user actions on these approved models at the production folder level. However, it appears that someone has overwritten the policy. This has allowed developers to access third-party models on a particular production project. You need to resolve the issue with a solution that prevents a repeat occurrence. What should you do?
A) Withdraw the Organization Policy Administrator role from all non-security team principals at the organization level.
B) Withdraw the Organization Policy Administrator role from all non-security team principals at the production folder level.
C) Implement a security posture based on the secure_ai_extended template to notify the security team of any policy changes at the organization level.
D) Implement a security posture based on the secure_ai_extended template to notify the security team of any policy changes at the production folder level.

Google Professional Cloud Security Engineer Exam - Topic 1 Question 123 Discussion

Actual exam question for Google's Professional Cloud Security Engineer exam
Question #: 123
Topic #: 1
[All Professional Cloud Security Engineer Questions]

The CISO of your highly regulated organization has mandated that all AI applications running in production must be based on Google first-party models. Your security team has now implemented the Model Garden's organization policy meant to centrally control access and user actions on these approved models at the production folder level. However, it appears that someone has overwritten the policy. This has allowed developers to access third-party models on a particular production project. You need to resolve the issue with a solution that prevents a repeat occurrence. What should you do?

Show Suggested Answer Hide Answer
Suggested Answer: A

In the Google Cloud resource hierarchy, Organization Policy is a powerful tool for governance, but its effectiveness depends on strict control over who can modify it. If a policy set at the folder level was 'overwritten,' it means a principal with the Organization Policy Administrator role (roles/orgpolicy.policyAdmin) at the project level (or folder level) changed the inheritance or defined a more permissive policy.1

According to Google Cloud Documentation (Organization Policy Service - IAM Roles):

'To manage organization policies, a principal must have the Organization Policy Administrator role. This role should be granted only at the Organization level to a limited set of trusted security or compliance administrators to prevent project owners from overriding security guardrails.'

Why Option A is the best fix:

By removing the role from everyone except the central security team at the Organization level, you ensure that no one else has the technical permission to 'Manage Policy' or click 'Override' at any child node (folder or project).

B is insufficient because if a user has the role at the organization level, they can still apply overrides at the folder or project level.

C and D (Security Postures) are detective controls. While the secure_ai_extended template helps monitor drift, it does not prevent the occurrence. The question asks for a solution that 'prevents a repeat occurrence,' which requires a preventative IAM change.


Google Cloud Security Engineer Study Guide: Chapter 2 - Resource Management and Access Control.

Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel