🔥 40% Off Crucial Exams Memberships — Deal ends today!

23 minutes, 43 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company hosts a proprietary fraud-detection model in Vertex AI, and the model artifacts reside in its managed Cloud Storage bucket. Security architects need a control that blocks any API or console attempt-even by users with Vertex AI Model Admin privileges-to copy these artifacts to resources in projects that are outside a defined set, while still allowing normal operations inside that set. Which Google Cloud capability best enforces this data-egress restriction?

  • Require all callers to authenticate through Workload Identity Federation instead of long-lived service account keys.

  • Encrypt the model artifacts with a customer-managed encryption key (CMEK) on the Cloud Storage bucket.

  • Place Vertex AI and the Cloud Storage bucket inside the same VPC Service Controls perimeter to block egress to resources outside that perimeter.

  • Attach a Cloud Armor security policy to the Vertex AI endpoint to deny requests that download model artifacts.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot