nerdexam
Google

PROFESSIONAL-CLOUD-ARCHITECT · Question #326

Your company has a Google Cloud project that uses BigOuery for data warehousing. The VPN tunnel between the on-premises environment and Google Cloud is configured with Cloud VPN. Your security team…

The correct answer is B. Configure VPC Service Controls and configure Private Google Access for on-promises hosts. VPC Service Controls help to establish security perimeters around Google Cloud services like BigQuery to prevent data exfiltration. They enforce restrictions on what resources can be accessed and from where. Private Google Access allows on-premises hosts to access Google APIs…

Submitted by thandi_sa· Mar 30, 2026Designing for security and compliance

Question

Your company has a Google Cloud project that uses BigOuery for data warehousing. The VPN tunnel between the on-premises environment and Google Cloud is configured with Cloud VPN. Your security team wants to avoid data exfiltration by malicious insiders, compromised code, and accidental oversharing. What should you do?

Options

  • AConfigure Private Service Connect.
  • BConfigure VPC Service Controls and configure Private Google Access for on-promises hosts.
  • CCreate a service account, grant the BigQuery JobUser role and Storage Object Viewer role to the
  • DConfigure Private Google Access.

How the community answered

(49 responses)
  • A
    4% (2)
  • B
    82% (40)
  • C
    12% (6)
  • D
    2% (1)

Explanation

VPC Service Controls help to establish security perimeters around Google Cloud services like BigQuery to prevent data exfiltration. They enforce restrictions on what resources can be accessed and from where. Private Google Access allows on-premises hosts to access Google APIs and services securely over a VPN or Interconnect, without traversing the public internet.

Topics

#VPC Service Controls#Private Google Access#data exfiltration#BigQuery security

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-ARCHITECT Practice