Scoped Access Context Manager Policy for Folder-Level BigQuery Restrictions | PCSE
You are implementing communications restrictions for specific services in your Google Cloud organization. Your data analytics team works in a dedicated folder. You need to ensure that access to BigQuery is controlled for that folder and its projects. The data analytics team must be able to control the restrictions only at the folder level. What should you do?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of Access Context Manager scoping; the trap is choosing an organization-wide policy instead of a folder-scoped one when management rights are limited to a specific folder.
This question tests how to apply granular service access controls in Google Cloud using Access Context Manager. It establishes that a scoped policy combined with a service perimeter is the correct method to restrict BigQuery access specifically at the folder level.
Selecting option A (organization-level policy) because candidates overlook the explicit requirement that restrictions must be managed solely at the folder level, leading to over-permissive or misaligned governance scopes.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option B correctly leverages Access Context Manager’s scoped policies to apply a service perimeter exclusively to the designated folder and its child projects. By defining a service perimeter around BigQuery, you enforce strict communications restrictions and data boundary controls exactly where needed. Granting the IAM role Access Context Manager Editor on that specific scoped policy ensures the analytics team retains administrative control without gaining visibility into other organizational policies.Why the Other Options Are Wrong
Option A creates an organization-wide policy, which violates the requirement to restrict and manage controls solely at the folder level. Option C relies on hierarchical firewall policies, which govern network-layer traffic rather than application-level service access and cannot enforce the granular API-based restrictions required here. Option D uses Organization Policy constraints, which limit service enablement but do not provide the secure perimeter enforcement or communications restrictions described in the scenario.Community Comment Notes
Learners consistently validate option B by emphasizing that scoped policies isolate restrictions to the target folder while preserving delegated administrative rights. As user Pime13 noted, "apply a service perimeter specifically to the folder". Multiple contributors highlight that the combination of folder-level scoping and targeted IAM roles perfectly satisfies both the technical and governance requirements of the question.Official Reference
Exam Strategy
Always match the scope of the policy to the exact resource hierarchy mentioned in the prompt. When a question specifies management rights limited to a single folder or project, immediately eliminate organization-wide configurations and look for scoped policy options paired with appropriate IAM roles.
Frequently Asked Questions
Why can't I use an organization-level policy here?
Organization-level policies apply across the entire enterprise, violating the requirement to manage restrictions solely at the folder level. Scoped policies isolate governance to the target folder and its projects.
Does a service perimeter replace IAM roles?
No. Service perimeters enforce network and data boundary restrictions, while IAM roles control who can configure and manage those policies. Both are required for proper implementation.