nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #378

Your organization has established a highly sensitive project within a VPC Service Controls perimeter. You need to ensure that only users meeting specific contextual requirements such as having a…

The correct answer is A. Establish a Context-Aware Access policy that specifies the required contextual attributes, and. To safely test access restrictions without disrupting legitimate access, you should create a Context-Aware Access policy that enforces conditions such as device management, user identity, and location, and then apply it to the VPC Service Controls perimeter in dry run mode. Dry…

Submitted by stefanr· Apr 18, 2026Configuring access within a cloud solution environment

Question

Your organization has established a highly sensitive project within a VPC Service Controls perimeter. You need to ensure that only users meeting specific contextual requirements such as having a company-managed device, a specific location, and a valid user identity can access resources within this perimeter. You want to evaluate the impact of this change without blocking legitimate access. What should you do?

Options

  • AEstablish a Context-Aware Access policy that specifies the required contextual attributes, and
  • BUse the VPC Service Control Violation dashboard to identify the impact of details about access
  • CConfigure a VPC Service Controls perimeter in dry run mode, and enforce strict network
  • DUse Cloud Audit Logs to monitor user access to the project resources. Use post-incident analysis

How the community answered

(28 responses)
  • A
    71% (20)
  • B
    4% (1)
  • C
    18% (5)
  • D
    7% (2)

Explanation

To safely test access restrictions without disrupting legitimate access, you should create a Context-Aware Access policy that enforces conditions such as device management, user identity, and location, and then apply it to the VPC Service Controls perimeter in dry run mode. Dry run mode allows you to evaluate the policy’s impact and review potential access denials before enforcing the restrictions, ensuring a smooth and compliant rollout.

Topics

#Context-Aware Access#Access Context Manager#Policy evaluation#VPC Service Controls

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice