PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #322
You manage a Google Cloud organization with many projects located in various regions around the world. The projects are protected by the same Access Context Manager access policy. You created a new…
The correct answer is C. - Edit the organization-level access policy and add the new folder under "Select resources to. Option C is correct because VPC Service Controls service perimeters are managed within an Access Context Manager access policy, and since the organization already has one organization-level policy, the right approach is to edit that existing policy - creating a new service…
Question
Options
- A
- Create a scoped access policy, add the new folder under "Select resources to include in the
- B
- Enable Identity Aware Proxy in the new projects.
- C
- Edit the organization-level access policy and add the new folder under "Select resources to
- D
- Configure a Cloud Interconnect connection or a Virtual Private Network (VPN) between the on-
How the community answered
(26 responses)- A4% (1)
- B8% (2)
- C85% (22)
- D4% (1)
Explanation
Option C is correct because VPC Service Controls service perimeters are managed within an Access Context Manager access policy, and since the organization already has one organization-level policy, the right approach is to edit that existing policy - creating a new service perimeter scoped to the two PHI projects, configuring a US-based geo access level, and restricting allowed services to BigQuery and Cloud Storage only.
Option A is wrong because a scoped access policy is used to delegate VPC SC management to a sub-team for a folder/project, not to layer stricter controls on top of an existing org policy. Resources can only belong to one access policy's perimeter, so creating a separate scoped policy would actually pull those projects out of the org-level policy's protection rather than adding to it.
Option B is wrong because Identity-Aware Proxy controls access to applications and VMs (HTTP/HTTPS traffic), not Google Cloud API calls. It has no role in restricting which Google Cloud services (BigQuery, Cloud Storage) are accessible within a VPC perimeter.
Option D is wrong because Cloud Interconnect/VPN provides network connectivity between on-premises and Google Cloud - it does nothing to enforce API restrictions or geo-based access controls through VPC Service Controls.
Memory tip: Think of the org-level access policy as the one security rulebook for the whole organization. To add a stricter chapter for PHI projects, you edit the existing book (Option C) - you don't write a separate book (scoped policy) or install a door lock (IAP) or dig a tunnel (VPN).
Topics
Community Discussion
No community discussion yet for this question.