exam questions

Exam Professional Cloud Architect All Questions

View all questions & answers for the Professional Cloud Architect exam

Exam Professional Cloud Architect topic 1 question 115 discussion

Actual exam question from Google's Professional Cloud Architect
Question #: 115
Topic #: 1
[All Professional Cloud Architect Questions]

Your company has sensitive data in Cloud Storage buckets. Data analysts have Identity Access Management (IAM) permissions to read the buckets. You want to prevent data analysts from retrieving the data in the buckets from outside the office network. What should you do?

  • A. 1. Create a VPC Service Controls perimeter that includes the projects with the buckets. 2. Create an access level with the CIDR of the office network.
  • B. 1. Create a firewall rule for all instances in the Virtual Private Cloud (VPC) network for source range. 2. Use the Classless Inter-domain Routing (CIDR) of the office network.
  • C. 1. Create a Cloud Function to remove IAM permissions from the buckets, and another Cloud Function to add IAM permissions to the buckets. 2. Schedule the Cloud Functions with Cloud Scheduler to add permissions at the start of business and remove permissions at the end of business.
  • D. 1. Create a Cloud VPN to the office network. 2. Configure Private Google Access for on-premises hosts.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Community vote distribution
A (100%)

Comments

Chosen Answer:
This is a voting comment. You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TotoroChina
Highly Voted 3 years, 3 months ago
Should be A. For all Google Cloud services secured with VPC Service Controls, you can ensure that: Resources within a perimeter are accessed only from clients within authorized VPC networks using Private Google Access with either Google Cloud or on-premises. https://cloud.google.com/vpc-service-controls/docs/overview
upvoted 72 times
ArtistS
10 months, 2 weeks ago
Enforce a security perimeter with VPC Service Controls to isolate resources of multi-tenant Google Cloud services—reducing the risk of data exfiltration or data breach.
upvoted 1 times
...
poseidon24
3 years, 2 months ago
Correct, this is about data exfiltration. See: https://youtu.be/EXwJFL24QzY
upvoted 14 times
Sivanaga
2 years ago
nice one, thank you man
upvoted 2 times
...
mv2000
2 years, 3 months ago
Thanks for including the youtube video it was very helpful
upvoted 1 times
...
...
...
XDevX
Highly Voted 3 years, 3 months ago
IMHO c is wrong - the question is not to restrict access only for business hours but to restrict access to office network. In my opinion the only realistic approach seems to be a) https://cloud.google.com/vpc-service-controls/docs/supported-products#table_storage
upvoted 17 times
...
plumbig11
Most Recent 2 months, 4 weeks ago
Selected Answer: A
In this case a VPC Service Controls , is more appropriated.
upvoted 1 times
...
19040e5
4 months, 1 week ago
Selected Answer: A
It's obviously A. C mentions office hours which has nothing to do with the question!
upvoted 1 times
...
Gino17m
5 months, 2 weeks ago
Selected Answer: A
A is correct answer. Examtopics should change so-called "Correct Answer" from C to A to stop confusin users.
upvoted 2 times
...
kalyan_krishna742020
5 months, 3 weeks ago
I'm preparing for a test and see that questions from 115 onwards are considered valid. Can anyone who's taken the test offer any insights or advice? Thank you!
upvoted 1 times
...
discuss24
8 months, 4 weeks ago
A is the correct answer. The question is specific to accessing the data outside of the office network. If the question talked about outside of work business hours then, we can consider C
upvoted 1 times
...
JPA210
11 months, 3 weeks ago
How can be possible that Examtopics say that the correct answer is C?! It doesn't make any sense! A is the correct one.
upvoted 2 times
...
heretolearnazure
1 year, 1 month ago
A is correct answer
upvoted 1 times
...
RVivek
1 year, 8 months ago
Selected Answer: A
https://cloud.google.com/vpc-service-controls/docs/overview
upvoted 1 times
...
vamgcp
1 year, 8 months ago
A is correct because, For all Google Cloud services secured with VPC Service Controls, you can ensure that resources within a perimeter are accessed only from clients within authorized VPC networks using Private Google Access with either Google Cloud or on-premises.
upvoted 1 times
...
examch
1 year, 9 months ago
Selected Answer: A
A is the correct answer, https://cloud.google.com/vpc-service-controls/docs/overview#isolate * A VM within a Virtual Private Cloud (VPC) network that is part of a service perimeter can read from or write to a Cloud Storage bucket in the same perimeter. However, VPC Service Controls doesn't allow VMs within VPC networks that are outside the perimeter to access Cloud Storage buckets that are inside the perimeter. * A copy operation between two Cloud Storage buckets succeeds if both buckets are in the same service perimeter, but if one of the buckets is outside the perimeter, the copy operation fails. * VPC Service Controls doesn't allow a VM within a VPC network that is inside a service perimeter to access Cloud Storage buckets that are outside the perimeter.
upvoted 4 times
...
thamaster
1 year, 9 months ago
Selected Answer: A
answer C will not prevent connection from outside of office network
upvoted 1 times
...
cshubham173
1 year, 9 months ago
Selected Answer: A
For all Google Cloud services secured with VPC Service Controls, you can ensure that: Resources within a perimeter are accessed only from clients within authorized VPC networks using Private Google Access with either Google Cloud or on-premises. https://cloud.google.com/vpc-service-controls/docs/overview
upvoted 2 times
...
megumin
1 year, 10 months ago
Selected Answer: A
A is ok
upvoted 1 times
...
minmin2020
1 year, 11 months ago
Selected Answer: A
A. Best option B. Not all instances need this restriction C. You are not restricting remote access. The users can still access remotely using their credentials during the business day. The ask is to restrict data retrieval from outside the office network (what if they are working from home...?) D. VPN - too much overhead
upvoted 1 times
...
minmin2020
1 year, 11 months ago
A. Best option B. Not all instances need this restriction C. You are not restricting remote access. The users can still access remotely using their credentials during the business day. The ask is to restrict data retrieval from outside the office network (what if they are working from home...?) D. VPN - too much overhead
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
220-1102
Doha, 1 minute ago