nerdexam
Google

PROFESSIONAL-DATA-ENGINEER · Question #267

The Development and External teams have the project viewer Identity and Access Management (IAM) role in a folder named Visualization. You want the Development Team to be able to read data from both…

The correct answer is D. Create a VPC Service Controls perimeter containing both protects and Cloud Storage as a restricted API. Add the Development Team users to the perimeter's. Explanation/Reference: Extend perimeters to authorized VPN or Cloud Interconnect You can configure private communication to Google Cloud resources from VPC networks that span hybrid environments with Private Google Access on-premises extensions. A VPC network must be part of a…

Submitted by thandi_sa· Mar 30, 2026Ensuring solution quality

Question

The Development and External teams have the project viewer Identity and Access Management (IAM) role in a folder named Visualization. You want the Development Team to be able to read data from both Cloud Storage and BigQuery, but the External Team should only be able to read data from BigQuery. What should you do?

Exhibit

PROFESSIONAL-DATA-ENGINEER question #267 exhibit

Options

  • ARemove Cloud Storage IAM permissions to the External Team on the acme-raw-data project
  • BCreate Virtual Private Cloud (VPC) firewall rules on the acme-raw-data protect that deny all Ingress traffic from the External Team CIDR range
  • CCreate a VPC Service Controls perimeter containing both protects and BigQuery as a restricted API Add the External Team users to the perimeter s Access
  • DCreate a VPC Service Controls perimeter containing both protects and Cloud Storage as a restricted API. Add the Development Team users to the perimeter's

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    17% (4)
  • D
    71% (17)

Explanation

Explanation/Reference: Extend perimeters to authorized VPN or Cloud Interconnect You can configure private communication to Google Cloud resources from VPC networks that span hybrid environments with Private Google Access on-premises extensions. A VPC network must be part of a service perimeter for VMs on that network to privately access managed Google Cloud resources within that service https://cloud.google.com/vpc-service-controls/docs/overview#internet

Topics

#VPC Service Controls#IAM roles#BigQuery access#Cloud Storage access

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-DATA-ENGINEER Practice