PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #353
Your organization is implementing a Zero Trust security model and using Chrome Enterprise Premium. The company is interested in governing access to sensitive data stored in Cloud Storage. You need…
The correct answer is C. Create an access level in Access Context Manager that requires a device policy. Create a. This setup enforces Zero Trust by using Access Context Manager to define a device-based access level (e.g., requiring up-to-date OS patches and antivirus via device policy), then applying that via Context-Aware Access to control access into the VPC Service Controls perimeter…
Question
Options
- AGrant access to specific users to the VPC Service Controls to create a perimeter to access the
- BConfigure IAM conditions based on IP address ranges. Require users to connect through a VPN.
- CCreate an access level in Access Context Manager that requires a device policy. Create a
- DUse Cloud Firewall rules to restrict access to the Cloud Storage buckets based on the source IP
How the community answered
(20 responses)- A5% (1)
- B10% (2)
- C80% (16)
- D5% (1)
Explanation
This setup enforces Zero Trust by using Access Context Manager to define a device-based access level (e.g., requiring up-to-date OS patches and antivirus via device policy), then applying that via Context-Aware Access to control access into the VPC Service Controls perimeter around the Cloud Storage data - ensuring only authorized users on compliant managed devices can reach the buckets regardless of network location.
Topics
Community Discussion
No community discussion yet for this question.