🔥 40% Off Crucial Exams Memberships — Deal ends today!

45 minutes, 55 seconds remaining!

GCP Professional Cloud Architect Practice Question

Your company processes protected health information on Google Cloud. Compliance requires that trained models and online prediction requests never traverse the public internet and that no other Google Cloud project can access them. A Cloud Run service in the same project will invoke the model for real-time inference. What architecture best meets these requirements while following the principle of least privilege?

  • Keep the default public Vertex AI endpoint, secure it with Cloud Armor rules that allow traffic only from Cloud Run egress IPs, and store the model in a multi-region Cloud Storage bucket with uniform bucket-level access.

  • Create a VPC Service Controls perimeter that includes the project. Deploy the model to a Vertex AI endpoint configured with a Private Service Connect network and disable public access. Grant the Cloud Run service account only the Vertex AI predict permission and call the endpoint over the PSC internal address.

  • Enable Cloud NAT for the VPC and configure firewall rules to block all egress except to the public Vertex AI predict service; authenticate from Cloud Run using a service account key stored in Secret Manager.

  • Expose the Vertex AI endpoint through Cloud Endpoints behind an internal HTTP(S) load balancer and protect it with an API key; store model artifacts in a private BigQuery dataset with row-level security.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot