GCP Professional Cloud Security Engineer Practice Question

Your security team is adopting a zero-trust model for workloads on Google Cloud. They must:

  • Allow users to invoke Google Cloud APIs and use the Cloud Console only when requests come from company-managed devices located within the enterprise's public IP ranges.
  • Ensure that data in the payments project cannot be copied to resources in any other Google Cloud project or to external services, even by authorized users. Which approach leverages Access Context Manager to meet both requirements with minimal configuration overhead?
  • Implement VPC firewall rules to allow only corporate IPs and deploy a Cloud Armor security policy in front of BigQuery.

  • Create one access level that combines the device and IP conditions, and place the payments project inside a service perimeter.

  • Set an Organization Policy that blocks external data transfers and attach IAM conditions with IP constraints to every BigQuery dataset.

  • Create two separate access levels-one for device compliance and one for IP range-and assign them to the payments project.

GCP Professional Cloud Security Engineer
Configuring Access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot