nerdexam
Google

PROFESSIONAL-CLOUD-ARCHITECT · Question #208

Your company has sensitive data in Cloud Storage buckets. Data analysts have Identity Access Management (IAM) permissions to read the buckets. You want to prevent data analysts from retrieving the dat

The correct answer is A. 1. Create a VPC Service Controls perimeter that includes the projects with the buckets.. For all Google Cloud services secured with VPC Service Controls, you can ensure that: Resources within a perimeter are accessed only from clients within authorized VPC networks using Private Google Access with either Google Cloud or on-premises. https://cloud.google.com/vpc-servi

Submitted by priya_blr· Mar 30, 2026Designing for security and compliance

Question

Your company has sensitive data in Cloud Storage buckets. Data analysts have Identity Access Management (IAM) permissions to read the buckets. You want to prevent data analysts from retrieving the data in the buckets from outside the office network. What should you do?

Options

  • A
    1. Create a VPC Service Controls perimeter that includes the projects with the buckets.
  • B
    1. Create a firewall rule for all instances in the Virtual Private Cloud (VPC) network for source
  • C
    1. Create a Cloud Function to remove IAM permissions from the buckets, and another Cloud
  • D
    1. Create a Cloud VPN to the office network.

How the community answered

(37 responses)
  • A
    81% (30)
  • B
    11% (4)
  • C
    3% (1)
  • D
    5% (2)

Explanation

For all Google Cloud services secured with VPC Service Controls, you can ensure that: Resources within a perimeter are accessed only from clients within authorized VPC networks using Private Google Access with either Google Cloud or on-premises. https://cloud.google.com/vpc-service-controls/docs/overview

Topics

#VPC Service Controls#Cloud Storage#data exfiltration prevention#IAM

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-ARCHITECT Practice