nerdexam
Google

PROFESSIONAL-CLOUD-ARCHITECT · Question #249

Your company has a Google Cloud project that uses BigQuery for data warehousing. They have a VPN tunnel between the on-premises environment and Google Cloud that is configured with Cloud VPN. The secu

The correct answer is C. Configure VPC Service Controls and configure Private Google Access.. Data exfiltration by malicious insiders or compromised code: VPC Service Controls complements network egress controls by preventing clients within those networks from accessing the resources of Google-managed services outside the perimeter. https://cloud.google.com/vpc-service-co

Submitted by akirajp· Mar 30, 2026Designing for security and compliance

Question

Your company has a Google Cloud project that uses BigQuery for data warehousing. They have a VPN tunnel between the on-premises environment and Google Cloud that is configured with Cloud VPN. The security team wants to avoid data exfiltration by malicious insiders, compromised code, and accidental oversharing. What should they do?

Options

  • AConfigure Private Google Access for on-premises only.
  • BPerform the following tasks:
  • CConfigure VPC Service Controls and configure Private Google Access.
  • DConfigure Private Google Access.

How the community answered

(28 responses)
  • A
    11% (3)
  • B
    18% (5)
  • C
    64% (18)
  • D
    7% (2)

Explanation

Data exfiltration by malicious insiders or compromised code: VPC Service Controls complements network egress controls by preventing clients within those networks from accessing the resources of Google-managed services outside the perimeter. https://cloud.google.com/vpc-service-controls/docs/overview

Topics

#VPC Service Controls#data exfiltration prevention#BigQuery security#Private Google Access

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-ARCHITECT Practice