GCP Professional Cloud Security Engineer Practice Question

Your company is building a Vertex AI custom-training workflow that processes sensitive financial data stored in Cloud Storage. Compliance mandates that (1) the training VMs must not have external IP addresses, (2) all traffic between the training service, Cloud Storage, and Vertex AI APIs must stay on Google's private network, and (3) any egress to Google-managed services outside an approved boundary must be blocked. The training image still needs to pull Python packages from an Artifact Registry repository in the same project. Which network design satisfies these requirements while keeping operational overhead low?

  • Configure Private Service Connect endpoints for Vertex AI and Cloud Storage but allow training VMs to keep their external IPs; rely on Cloud Armor policies to block traffic to unauthorized Google APIs.

  • Create a VPC Service Controls perimeter that includes Vertex AI, Cloud Storage, and Artifact Registry; configure Private Service Connect endpoints for Vertex AI APIs; run training jobs in a private subnet that has Private Google Access enabled and no external IP addresses.

  • Enable Private Google Access on the default VPC and apply an organization policy that denies external IPs for Compute Engine; do not configure VPC Service Controls or Private Service Connect.

  • Disable external IPs on the training VMs and use a Cloud NAT gateway; restrict egress with firewall rules so only Cloud Storage and Artifact Registry IP ranges are allowed.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot