Your security policy requires blocking creation of VMs with external IPv4 addresses across the organization except in one security project. Which organization policy constraint should you configure to enforce this?
Choose an answer
Tap an option to check your answer.
Correct answer: constraints/compute.vmExternalIpAccess.
Why this is the answer
The constraints/compute.vmExternalIpAccess organization policy constraint directly controls whether VMs can be created with external IPv4 addresses. By setting this constraint to deny all external IP access at the organization level, and then creating an exception for the designated security project, you can enforce the described security policy. constraints/iam.allowedPolicyMemberDomains restricts which domains can be used for IAM policy members, not VM external IP access. constraints/compute.restrictNetworkCreation controls who can create VPC networks, not the assignment of external IPs to VMs within those networks. constraints/servicemanagement.disableServiceUsage prevents the use of specific Google Cloud services, which is unrelated to VM external IP configuration.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed