🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 53 minutes remaining!

GCP Professional Cloud Architect Practice Question

Your security team mandates that BigQuery data in the analytics-prod project must only be queried from Google-managed laptops that comply with company endpoint policies. In addition, the data must never be copied to projects outside analytics-prod, even if an IAM administrator accidentally grants BigQuery roles to another project's service account. Which security control design best meets both requirements?

  • Configure an organization-level hierarchical firewall policy that blocks all egress except to the corporate VPN and turn on BigQuery Data Access audit logs in analytics-prod.

  • Create a VPC Service Controls perimeter around analytics-prod and add an Access Context Manager access level that allows requests only from corporate-managed devices, denying all other egress.

  • Enable Cloud Identity-Aware Proxy for BigQuery, create a context-aware access policy requiring compliant devices, and export BigQuery audit logs to Cloud Storage for additional monitoring.

  • Apply an organization policy that disables cross-project data export and enforces CMEK for BigQuery, while routing all traffic through Cloud NAT private IP ranges.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot