Enforce a policy that external (public) IP addresses are allowed only on approved VM instances across all VPCs. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Set an Organization Policy using the constraint constraints/compute.vmExternalIpAccess and list the approved instances in allowedValues..
Why this is the answer
The correct answer is to set an Organization Policy using the constraints/compute.vmExternalIpAccess constraint and list the approved instances in allowedValues. This Organization Policy constraint directly controls the ability to assign external IP addresses to VM instances. By applying this policy at the organization or folder level, you can enforce the rule across all VPCs and projects, ensuring that only explicitly allowed instances can have public IPs. Removing the default route on all VPCs and moving approved instances to a new subnet with a default route to an internet gateway is overly complex and disruptive, impacting all traffic, not just external IP assignment. Creating a new custom-mode VPC and subnet with a default route for approved instances doesn't prevent other instances in other VPCs from getting external IPs. Implementing Cloud NAT eliminates external IP addresses for outbound connections but doesn't enforce a policy to prevent their assignment in the first place.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed