Scoped Access Context Manager Policy for Folder-Level BigQuery Restrictions | PCSE

Access Context Manager & Security Perimeters
Answer Correct answer: B — Create a scoped Access Context Manager policy on the folder with a service perimeter to restrict BigQuery access, plus the Access Context Manager Editor role.

You are implementing communications restrictions for specific services in your Google Cloud organization. Your data analytics team works in a dedicated folder. You need to ensure that access to BigQuery is controlled for that folder and its projects. The data analytics team must be able to control the restrictions only at the folder level. What should you do?

  1. Create an organization-level access policy with a service perimeter to restrict BigQuery access. Assign the data analytics team the Access Context Manager Editor role on the access policy to allow the team to configure the access policy.
  2. Create a scoped policy on the folder with a service perimeter to restrict BigQuery access. Assign the data analytics team the Access Context Manager Editor role on the scoped policy to allow the team to configure the scoped policy. Correct Answer
  3. Define a hierarchical firewall policy on the folder to deny BigQuery access. Assign the data analytics team the Compute Organization Firewall Policy Admin role to allow the team to configure rules for the firewall policy.
  4. Enforce the Restrict Resource Service Usage organization policy constraint on the folder to restrict BigQuery access. Assign the data analytics team the Organization Policy Administrator role to allow the team to manage exclusions within the folder.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of Access Context Manager scoping; the trap is choosing an organization-wide policy instead of a folder-scoped one when management rights are limited to a specific folder.

This question tests how to apply granular service access controls in Google Cloud using Access Context Manager. It establishes that a scoped policy combined with a service perimeter is the correct method to restrict BigQuery access specifically at the folder level.

Selecting option A (organization-level policy) because candidates overlook the explicit requirement that restrictions must be managed solely at the folder level, leading to over-permissive or misaligned governance scopes.

Community Discussion (4 comments)

Pime13 👍 1 Selected: B
This approach allows you to apply a service perimeter specifically to the folder, ensuring that BigQuery access is controlled at the desired level. By assigning the Access Context Manager Editor role to the data analytics team, you enable them to manage the scoped policy as needed.
MoAk 👍 1 Selected: B
B is good.
KLei 👍 1 Selected: B
Scoped Policy: A scoped policy allows you to apply restrictions specifically to a folder and its projects Service Perimeter: By using a service perimeter, you can define which services (like BigQuery) can be accessed from within the specified folder.
yokoyan 👍 3 Selected: B
I think it's B.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B correctly leverages Access Context Manager’s scoped policies to apply a service perimeter exclusively to the designated folder and its child projects. By defining a service perimeter around BigQuery, you enforce strict communications restrictions and data boundary controls exactly where needed. Granting the IAM role Access Context Manager Editor on that specific scoped policy ensures the analytics team retains administrative control without gaining visibility into other organizational policies.

Why the Other Options Are Wrong

Option A creates an organization-wide policy, which violates the requirement to restrict and manage controls solely at the folder level. Option C relies on hierarchical firewall policies, which govern network-layer traffic rather than application-level service access and cannot enforce the granular API-based restrictions required here. Option D uses Organization Policy constraints, which limit service enablement but do not provide the secure perimeter enforcement or communications restrictions described in the scenario.

Community Comment Notes

Learners consistently validate option B by emphasizing that scoped policies isolate restrictions to the target folder while preserving delegated administrative rights. As user Pime13 noted, "apply a service perimeter specifically to the folder". Multiple contributors highlight that the combination of folder-level scoping and targeted IAM roles perfectly satisfies both the technical and governance requirements of the question.

Official Reference

Exam Strategy

Always match the scope of the policy to the exact resource hierarchy mentioned in the prompt. When a question specifies management rights limited to a single folder or project, immediately eliminate organization-wide configurations and look for scoped policy options paired with appropriate IAM roles.

Frequently Asked Questions

Why can't I use an organization-level policy here?

Organization-level policies apply across the entire enterprise, violating the requirement to manage restrictions solely at the folder level. Scoped policies isolate governance to the target folder and its projects.

Does a service perimeter replace IAM roles?

No. Service perimeters enforce network and data boundary restrictions, while IAM roles control who can configure and manage those policies. Both are required for proper implementation.

Related Analysis

← Back to PCSE Study Guide