GCP Professional Cloud Security Engineer Practice Question

You are implementing a BeyondCorp security model for an internal HR self-service portal that will run on Cloud Run and be protected by Cloud IAP. Only employees using company-managed devices that satisfy minimum security posture (screen lock and encryption) and that originate from the corporate VPN's CIDR block should be able to reach the service. With minimal ongoing operational effort, which Access Context Manager configuration will best enforce these requirements?

  • Place the HR project in a VPC Service Controls perimeter and configure ingress and egress rules to allow traffic only from the VPN subnet and trusted devices.

  • Grant all employees a custom IAM role with an IAM condition limiting access to the VPN subnet and requiring secure devices.

  • Apply an organization policy that blocks external IP access to the HR project and rely on Security Command Center to flag non-compliant devices.

  • Create a basic access level that includes the corporate VPN IPv4 subnet in ipSubnetworks and a device policy requiring verified, encrypted, company-managed devices, then associate this level with Cloud IAP for the HR service.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot