🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 0 minute remaining!

GCP Professional Cloud Security Engineer Practice Question

Your security team has enclosed two sensitive finance projects in a VPC Service Controls perimeter called finance-perimeter. Internal staff already access them through an existing high-trust access level. You must now let external consultants, who authenticate as members of the group [email protected], deploy and manage Cloud Run in those projects only between 09:00 and 17:00 UTC. Consultants must remain blocked from BigQuery, Cloud Storage, and every other Google Cloud API inside the perimeter. What should you do?

  • Add the [email protected] group as members of finance-perimeter and create a bridge perimeter that links a new consultants project, relying on IAM roles to limit them to Cloud Run.

  • Define a custom access level that requires membership in [email protected] and a request.time between 09:00 and 17:00 UTC, then add an ingress rule to finance-perimeter that allows only run.googleapis.com when this access level is matched.

  • Reuse the existing high-trust access level and add an egress rule on finance-perimeter that permits run.googleapis.com; leave other services unmodified.

  • Grant the consultants group the Cloud Run Admin role on the finance projects without changing the service perimeter, because IAM permissions override VPC Service Controls.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot