nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #322

You manage a Google Cloud organization with many projects located in various regions around the world. The projects are protected by the same Access Context Manager access policy. You created a new…

The correct answer is C. - Edit the organization-level access policy and add the new folder under "Select resources to. Option C is correct because VPC Service Controls service perimeters are managed within an Access Context Manager access policy, and since the organization already has one organization-level policy, the right approach is to edit that existing policy - creating a new service…

Submitted by takeshi77· Apr 18, 2026Configuring access within a cloud solution environment

Question

You manage a Google Cloud organization with many projects located in various regions around the world. The projects are protected by the same Access Context Manager access policy. You created a new folder that will host two projects that process protected health information (PHI) for US-based customers. The two projects will be separately managed and require stricter protections. You are setting up the VPC Service Controls configuration for the new folder. You must ensure that only US-based personnel can access these projects and restrict Google Cloud API access to only BigQuery and Cloud Storage within these projects. What should you do?

Options

  • A
    • Create a scoped access policy, add the new folder under "Select resources to include in the
  • B
    • Enable Identity Aware Proxy in the new projects.
  • C
    • Edit the organization-level access policy and add the new folder under "Select resources to
  • D
    • Configure a Cloud Interconnect connection or a Virtual Private Network (VPN) between the on-

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    85% (22)
  • D
    4% (1)

Explanation

Option C is correct because VPC Service Controls service perimeters are managed within an Access Context Manager access policy, and since the organization already has one organization-level policy, the right approach is to edit that existing policy - creating a new service perimeter scoped to the two PHI projects, configuring a US-based geo access level, and restricting allowed services to BigQuery and Cloud Storage only.

Option A is wrong because a scoped access policy is used to delegate VPC SC management to a sub-team for a folder/project, not to layer stricter controls on top of an existing org policy. Resources can only belong to one access policy's perimeter, so creating a separate scoped policy would actually pull those projects out of the org-level policy's protection rather than adding to it.

Option B is wrong because Identity-Aware Proxy controls access to applications and VMs (HTTP/HTTPS traffic), not Google Cloud API calls. It has no role in restricting which Google Cloud services (BigQuery, Cloud Storage) are accessible within a VPC perimeter.

Option D is wrong because Cloud Interconnect/VPN provides network connectivity between on-premises and Google Cloud - it does nothing to enforce API restrictions or geo-based access controls through VPC Service Controls.

Memory tip: Think of the org-level access policy as the one security rulebook for the whole organization. To add a stricter chapter for PHI projects, you edit the existing book (Option C) - you don't write a separate book (scoped policy) or install a door lock (IAP) or dig a tunnel (VPN).

Topics

#VPC Service Controls#Access Context Manager#Service Perimeters#Geographic Restrictions

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice