nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #353

Your organization is implementing a Zero Trust security model and using Chrome Enterprise Premium. The company is interested in governing access to sensitive data stored in Cloud Storage. You need…

The correct answer is C. Create an access level in Access Context Manager that requires a device policy. Create a. This setup enforces Zero Trust by using Access Context Manager to define a device-based access level (e.g., requiring up-to-date OS patches and antivirus via device policy), then applying that via Context-Aware Access to control access into the VPC Service Controls perimeter…

Submitted by andres_qro· Apr 18, 2026Configuring access within a cloud solution environment

Question

Your organization is implementing a Zero Trust security model and using Chrome Enterprise Premium. The company is interested in governing access to sensitive data stored in Cloud Storage. You need to configure access controls that ensure only authorized users on managed devices can access this data, regardless of their network location. Access should be restricted based on the device's security posture. This requires up-to-date operating system patches and antivirus software. What should you do?

Options

  • AGrant access to specific users to the VPC Service Controls to create a perimeter to access the
  • BConfigure IAM conditions based on IP address ranges. Require users to connect through a VPN.
  • CCreate an access level in Access Context Manager that requires a device policy. Create a
  • DUse Cloud Firewall rules to restrict access to the Cloud Storage buckets based on the source IP

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    10% (2)
  • C
    80% (16)
  • D
    5% (1)

Explanation

This setup enforces Zero Trust by using Access Context Manager to define a device-based access level (e.g., requiring up-to-date OS patches and antivirus via device policy), then applying that via Context-Aware Access to control access into the VPC Service Controls perimeter around the Cloud Storage data - ensuring only authorized users on compliant managed devices can reach the buckets regardless of network location.

Topics

#Zero Trust#Access Context Manager#Device Policy#Cloud Storage Security

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice