Cloud Identity and Organization are enabled. You must prevent users outside the domain from receiving IAM permissions going forward. What should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: Set an organization policy that restricts identities to the corporate domain..
Why this is the answer
Setting an organization policy that restricts identities to the corporate domain is the most effective and preventative solution. This policy, specifically the constraints/iam.allowedPolicyMemberDomains constraint, prevents any IAM policy binding from being created or updated if it includes a member from an unauthorized domain. This stops the problem at its source. Blocking service account creation is incorrect because service accounts are internal to GCP and don't directly relate to external user access. Using Cloud Scheduler with a Cloud Function or a Compute Engine VM with a cron job are reactive solutions. They would attempt to fix violations after they occur, rather than preventing them, and introduce unnecessary complexity and potential for race conditions or temporary access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed