Ultimate access to all questions.
Your company is using Google Cloud Platform, which is structured with an Organization node at the top, and it contains two primary folders: Finance and Shopping. The development team within your company is grouped into a Google Group. This group currently holds the Project Owner role at the Organization level, granting them the ability to create and manage all resources within the organization. However, there is a new requirement to restrict the development team from creating resources in any projects located within the Finance folder while maintaining their ability to manage resources in the Shopping folder. What should you do to achieve this restriction?
Explanation:
The correct answer is C: Assign the development team group the Project Owner role on the Shopping folder, and remove the development team group Project Owner role from the Organization. This is because permissions granted at the Organization level are inherited by all resources within the organization, including subfolders like Finance. To restrict the development team from creating resources in the Finance folder, you must remove their Project Owner role at the Organization level, then reassign the Project Owner role only to the Shopping folder. This way, they retain full control over projects within the Shopping folder but are restricted to minimal permissions in the Finance folder.