A large enterprise organizes its Google Cloud resources with an organization node, a 'security-controls' folder, and multiple team folders beneath it. The central security team defines a hierarchical firewall policy attached at the organization level that must enforce a mandatory deny on all inbound RDP (TCP 3389) from the internet, while allowing individual application teams to define their own rules for other traffic in their project-level network firewall policies. However, for a specific range of trusted corporate egress IPs, the security team wants lower-level policies and rules to be able to make the final allow/deny decision for RDP rather than having it blocked at the org level. Which configuration correctly meets these requirements?