🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 51 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

A healthcare organization manages multiple projects that process protected health information (PHI). You must expand the existing VPC Service Controls service perimeter to include a new BigQuery project called bq-analytics. Leadership worries that an overly strict perimeter might disrupt on-premises integrations that still rely on public endpoints. You need to demonstrate which requests would be denied before the perimeter is enforced, yet avoid any impact on production traffic. Which approach meets these requirements with minimal operational risk?

  • Rely on BigQuery Cloud Audit Logs in the bq-analytics project to detect permission-denied errors after enforcing the perimeter.

  • Add the bq-analytics project to the existing service perimeter's dry-run configuration, enable Cloud Logging for VPC Service Controls, and monitor the cloudaudit.googleapis.com/policy logs for violations.

  • First enable Private Google Access on all subnets, then move the bq-analytics project into an enforced perimeter; if issues occur, roll back the subnet setting.

  • Create a new enforced service perimeter that contains only the bq-analytics project and observe whether applications fail to connect.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot