Objective 1.5

PCSE

Defining the resource hierarchy

Objective 1.5 sits in Configuring access, which carries 25% of the Cloud Security Engineer exam. The questions below are original, written from the official objective title above, and each explanation cites the Google Cloud page it rests on.

Objective title verbatim from the official objectives. Google Cloud exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

1-5Configuring access

A platform team wants to see which workloads a proposed constraint would break before committing to it. Which mode does that?

Audit mode, enabled per constraint valueNo per-value audit setting exists on a constraint.
Active mode scoped to a single test folderA test folder still blocks the workloads that happen to live there.
Simulation mode, run from Policy IntelligencePolicy Simulator is a separate tool rather than a mode on the policy.
Dry-run mode, which logs and denies nothingCorrect · your answerCorrect. Nothing is refused while it runs.

Correct.

Concept

A restriction that has never been measured against live traffic is a guess. Observing what would have been refused, while refusing nothing, converts that guess into a list of owners to talk to.

Why D

An organization policy in dry-run mode is created and enforced like any other, but violations are only audit-logged and the violating actions are not denied.

Source

An organization policy in dry-run mode is created and enforced similarly to other organization policies, and violations of the policy are audit-logged, but the violating actions aren't denied. You can use organization policies in dry-run mode to monitor how policy changes would impact your workflows before they're enforced.

Google Cloud: Organization Policy overview, checked August 2026
#gcp#organization-policy#dry-run#constraints

Now you: objective 1.5 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

1-5Configuring access

An administrator lists one folder in an allowed values list and expects every project beneath it to be covered. Which prefix carries that meaning?

Sample question 2 of 3

1-5Configuring access

A team sets a list constraint allowing exactly two projects and leaves the denied list empty. How are the remaining values treated?

Sample question 3 of 3

1-5Configuring access

An organization applies a new location constraint and later finds resources already running outside the permitted regions. What does the service do with them?

Full Cloud Security Engineer question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Configuring access