Prevent external IPs on backend Compute Engine instances while allowing them only on frontend instances.
Choose an answer
Tap an option to check your answer.
Correct answer: Enforce an Organization Policy constraint that permits external IPs only on frontend Compute Engine instances..
Why this is the answer
The correct answer is to enforce an Organization Policy constraint. Organization Policies allow you to programmatically control your cloud resources, including restricting the creation of external IP addresses. By applying a constraint that permits external IPs only on frontend instances (e.g., by specifying allowed instance labels or projects), you ensure that backend instances cannot be provisioned with external IPs, regardless of user permissions. Revoking the compute.networkAdmin role from frontend users is incorrect because this role is typically needed for network configuration and doesn't directly prevent external IP assignment if other roles allow it. Mapping IT staff to compute.networkAdmin at the organization level is also incorrect as it grants broad permissions and doesn't restrict external IPs on backend instances. Creating a custom IAM role with compute.addresses.create is insufficient because it only controls who can create addresses, not where they can be attached, and doesn't enforce a policy across all instances.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed