GCP Professional Cloud Architect Practice Question

Your company runs an internal administrative dashboard on Cloud Run. Compliance rules require that only company-managed laptops running Chrome with full-disk encryption enabled and a recent OS patch level can reach the application from any network. The organization already authenticates users with Google Workspace identities and does not want to deploy VPN clients. As the cloud architect, which solution will most efficiently satisfy these requirements?

  • Protect the service with Cloud Armor and allow only requests whose HTTP User-Agent header matches an approved Chrome version; block all others.

  • Enroll laptops in Chrome Browser Cloud Management, deploy the Endpoint Verification extension, define an Access Level that requires encrypted, up-to-date managed devices, and attach this Access Level to the Cloud Run service's Identity-Aware Proxy policy.

  • Grant access only to employees via a custom IAM role and mandate two-step verification for their Google Workspace accounts, without additional device controls.

  • Put the Cloud Run service behind Private Service Connect, require users to connect through Cloud VPN from the corporate network, and enforce network-based firewall rules.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot