🔥 40% Off Crucial Exams Memberships — Deal ends today!

44 minutes, 43 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization has two Google Cloud projects. Project "prod-data" hosts BigQuery datasets containing protected health information (PHI). Project "analytics-tools" runs scheduled Dataflow jobs that must query those datasets. Security has issued these directives:

  • Prevent any PHI from being copied from BigQuery to the public internet or to projects outside the security boundary, even if IAM is misconfigured or credentials are exposed.
  • Permit Dataflow jobs to read the datasets only when the job workers originate from the corporate HQ's on-premises CIDR 203.0.113.0/24, reached over Cloud Interconnect.
  • Continue to allow "prod-data" to write stackdriver logging and monitoring data to their corresponding Google Cloud services without restriction.

What is the most effective and operationally efficient design to meet these requirements?

  • Remove all external IP addresses from resources in prod-data, apply an egress-deny VPC firewall rule, and set up VPC Network Peering with analytics-tools to permit private BigQuery access.

  • Add an IAM Condition on the BigQuery Data Viewer role limiting access to requests from 203.0.113.0/24 and configure Cloud Armor to block outbound traffic from prod-data to the public internet.

  • Create a single VPC Service Controls service perimeter that includes both projects, add BigQuery to the protected services list, define an access level restricted to 203.0.113.0/24 and attach it to the perimeter, and leave Cloud Logging and Monitoring to use their default perimeter-bridged access.

  • Enable customer-managed encryption keys (CMEK) for all BigQuery datasets in prod-data and grant the analytics-tools service accounts IAM BigQuery Data Viewer roles; rely on CMEK to prevent data exfiltration.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot