You define central security controls in your Google Cloud environment. For one of the folders in your organization, you set an organizational policy to deny the assignment of external IP addresses to VMs. Two days later, you receive an alert about a new VM with an external IP address under that folder. What could have caused this alert?
- AThe VM was created with a static external IP address that was reserved in the project before the organizational policy rule was set.
- BThe organizational policy constraint wasn't properly enforced and is running in "dry run" mode.
- CA project level, the organizational policy control has been overwritten with an "allow" value. (correct answer)
- DThe policy constraint on the folder level does not have any effect because of an "allow" value for that constraint on the organizational level.
Reveal answer & explanationHide answer
The correct answer is C. Option C: A project level, the organizational policy control has been overwritten with an "allow" value.