🔥 40% Off Crucial Exams Memberships — Deal ends today!

9 minutes, 33 seconds remaining!

GCP Professional Cloud Architect Practice Question

Your company is moving an internal reporting portal to Cloud Run (fully managed). The service will be published on a custom domain through an external HTTP(S) load balancer. Regulators require that only employees who 1) authenticate with their Google Workspace accounts, 2) use company-managed laptops validated by Endpoint Verification, and 3) originate traffic from EU member-state IP ranges can reach the portal. The security team wants a VPN-less solution managed from a single, organization-level control that can later be reused. What should you do?

  • Implement Identity Platform tokens verified by a Cloud Function that checks device serial numbers stored in Secret Manager, and place Cloud CDN in front of the load balancer to accept traffic only from EU locations.

  • Enable Identity-Aware Proxy on the load balancer and create an organization-level Context-Aware Access custom access level that requires Google Workspace authentication, Endpoint Verification-validated devices, and EU source IP ranges; attach this access level to the Cloud Run backend service.

  • Attach a Cloud Armor policy that blocks non-EU IP addresses, require staff to use the corporate VPN with allow-listed egress IPs, and grant employees the Cloud Run Invoker role.

  • Deploy the portal on a private Cloud Run service behind an internal load balancer and use Firebase Authentication in the application to restrict access from managed laptops.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot