🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 51 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company is building a PCI-DSS cardholder data environment (CDE) on Google Cloud. The CDE lives in a dedicated folder under the organization and spans multiple projects that share a host VPC. A control states: "Outbound traffic from any CDE subnet must be restricted to a short allow-list of compliance-scanner IPs. No other egress is permitted, and project admins must not bypass or remove the control." Which design meets this requirement while minimizing operational overhead?

  • Disable Private Google Access and Cloud NAT on the Shared VPC and expose the scanner IPs through external HTTP(S) load balancing so instances cannot send traffic elsewhere.

  • Create subnet-level egress deny rules in each CDE project with priority 1000 that block all destinations except the scanner IP range; instruct network admins in every project to keep the rules in place.

  • Configure a VPC Service Controls perimeter around the CDE projects and add the scanner IP range to the perimeter's access level; no additional firewall rules are required.

  • Attach a hierarchical firewall policy to the CDE folder that first allows egress to the scanner IPs, followed by a lower-priority rule that denies all other egress; ensure project owners lack firewall-policy admin rights.

GCP Professional Cloud Security Engineer
Supporting compliance requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot