GoogleGoogle
PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #175
PROFESSIONAL-CLOUD-SECURITY-ENGINEER Question #175: Real Exam Question with Answer & Explanation
The correct answer is C: Configure uniform bucket-level access, and enforce domain restricted sharing in an organization. Uniform bucket-level access: https://cloud.google.com/storage/docs/uniform-bucket-level- access#should-you-use - Domain Restricted Sharing: https://cloud.google.com/resource-manager/docs/organization- policy/restricting-domains#public_data_sharing
Submitted by haruto_sh· Apr 18, 2026Configuring access within a cloud solution environment
Question
You want to make sure that your organization's Cloud Storage buckets cannot have data publicly available to the internet. You want to enforce this across all Cloud Storage buckets. What should you do?
Options
- ARemove Owner roles from end users, and configure Cloud Data Loss Prevention.
- BRemove Owner roles from end users, and enforce domain restricted sharing in an organization
- CConfigure uniform bucket-level access, and enforce domain restricted sharing in an organization
- DRemove *.setIamPolicy permissions from all roles, and enforce domain restricted sharing in an
Explanation
- Uniform bucket-level access: https://cloud.google.com/storage/docs/uniform-bucket-level- access#should-you-use - Domain Restricted Sharing: https://cloud.google.com/resource-manager/docs/organization- policy/restricting-domains#public_data_sharing
Topics
#Cloud Storage Security#Uniform Bucket-Level Access#Organization Policies#Public Access Prevention
Community Discussion
No community discussion yet for this question.