PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #188
Your security team wants to implement a defense-in-depth approach to protect sensitive data stored in a Cloud Storage bucket. Your team has the following requirements: - The Cloud Storage bucket in…
The correct answer is B. Enable VPC Service Controls, create a perimeter around Projects A and B, and include the Cloud. VPC Peering is between organizations not between Projects in an organization. That is Shared VPC. In this case, both projects are in same organization so having VPC Service Controls around both projects with necessary rules should be fine…
Question
Options
- AEnable domain restricted sharing in an organization policy, and enable uniform bucket-level
- BEnable VPC Service Controls, create a perimeter around Projects A and B, and include the Cloud
- CEnable Private Access in both Project A and B's networks with strict firewall rules that allow
- DEnable VPC Peering between Project A and B's networks with strict firewall rules that allow
How the community answered
(33 responses)- A15% (5)
- B76% (25)
- C6% (2)
- D3% (1)
Explanation
VPC Peering is between organizations not between Projects in an organization. That is Shared VPC. In this case, both projects are in same organization so having VPC Service Controls around both projects with necessary rules should be fine. https://cloud.google.com/vpc-service-controls/docs/overview
Topics
Community Discussion
No community discussion yet for this question.