Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam Cloud Digital Leader All Questions

View all questions & answers for the Cloud Digital Leader exam

Exam Cloud Digital Leader topic 1 question 39 discussion

Actual exam question from Google's Cloud Digital Leader
Question #: 39
Topic #: 1
[All Cloud Digital Leader Questions]

Your organization needs to restrict access to a Cloud Storage bucket. Only employees who are based in Canada should be allowed to view the contents.
What is the most effective and efficient way to satisfy this requirement?

  • A. Deploy the Cloud Storage bucket to a Google Cloud region in Canada
  • B. Configure Google Cloud Armor to allow access to the bucket only from IP addresses based in Canada
  • C. Give each employee who is based in Canada access to the bucket
  • D. Create a group consisting of all Canada-based employees, and give the group access to the bucket
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Halimb
Highly Voted 2 years, 10 months ago
Selected Answer: D
Correct answer is D. Question is tricky, but it says "based" in Canada. That is not the same as restricting access to "from Canada". An employee can for instance be based in Canada, but access the services while on business trip to Singapore.
upvoted 36 times
...
Guru4Cloud
Highly Voted 11 months, 1 week ago
Selected Answer: D
Imagine a lock on your bucket. You want only Canadian employees to have keys. Here's the easiest way: Make a key club: Create a group called "Canada Keys". Add all Canadian employees: Give everyone in that group a key. Keep outsiders out: No key, no entry to the bucket! This way, you manage one key club instead of many individual keys, making it easier to add/remove people and keeping your bucket secure. Clear as day?
upvoted 6 times
...
Nishantkumar
Most Recent 1 month ago
Correct Option is B. Configure Google Cloud Armor to allow access to the bucket only from IP addresses based in Canada. Explanation: Google Cloud Armor provides security policies that can be applied to your Google Cloud services, including Cloud Storage. By configuring it to allow access only from Canadian IP addresses, you can effectively restrict access to the bucket based on geographical location. This approach ensures that only users connecting from Canada can access the bucket, aligning with your organization's requirement without needing to manage individual user permissions or groups.
upvoted 1 times
...
PanosPeris
6 months ago
Selected Answer: D
IP is a poor way to restrict access. Employees based in Canada could be working from anywhere.
upvoted 1 times
...
Wr5050
7 months, 3 weeks ago
Selected Answer: D
I found an excellent explanation on this site, the questions seem to be verified there https://techcertificationhelp.com/cloud-digital-leader/only-employees-who-are-based-in-canada-should-be-allowed-to-view-the-c
upvoted 3 times
...
MMeena
8 months, 4 weeks ago
Selected Answer: B
I think 'B' may be the option. question says "Only employees who are based in Canada" and considering the Google's security policy of 'Least Privilege Access' , option D, will give access to all Canada Employees, where they need to have access or not, which may be a security threat
upvoted 1 times
...
Pearl81
10 months, 2 weeks ago
If read carefully, question is granting access for "employees based in Canada" and not "employees in Canada". This makes a lot of different. Correct answer is D.
upvoted 3 times
Kunjesh9867
4 months, 2 weeks ago
Yes that is correct
upvoted 1 times
...
...
chai_gpt
1 year ago
Selected Answer: D
D is correct
upvoted 1 times
...
__rajan__
1 year, 1 month ago
Selected Answer: D
D is correct.
upvoted 1 times
...
Giuliano72
1 year, 1 month ago
Selected Answer: D
D in correct
upvoted 2 times
...
mdsarfraz69
1 year, 2 months ago
Selected Answer: B
B is correct
upvoted 1 times
...
oezgan
1 year, 2 months ago
Although a bit old I found this on Serverfault: "But, IP deny list/allow list for HTTP(S) Load Balancing is not supported for Cloud Storage backends. See Security Policy Concepts - Restrictions for details. " Thus, the answer must be D. (I Hope). Reference: https://serverfault.com/questions/992666/using-google-cloud-armor-to-block-requests-to-google-cloud-storage
upvoted 2 times
...
hireshgupt
1 year, 4 months ago
Selected Answer: D
Option D is the most effective and efficient way to restrict access to the bucket. Creating a group consisting of all Canada-based employees and giving the group access to the bucket will allow you to easily manage access to the bucket. You can add or remove employees from the group as needed, and you can give the group different levels of access to the bucket.
upvoted 3 times
...
ihavenonickname
1 year, 4 months ago
Selected Answer: D
ip restrictions can be bypassed
upvoted 1 times
...
cookieMr
1 year, 5 months ago
Selected Answer: D
To restrict access to a Cloud Storage bucket and ensure that only employees based in Canada can view its contents, you can use Cloud Identity and Access Management (Cloud IAM) in combination with Identity-Aware Proxy (IAP). By combining Cloud IAM and IAP, you can enforce fine-grained access control to the Cloud Storage bucket. Only employees based in Canada, as defined in the Cloud IAM roles and IAP access policy, will be able to view the bucket's contents. This provides an effective and efficient way to satisfy the access restriction requirement while leveraging Google Cloud's built-in identity and access management capabilities.
upvoted 3 times
...
Laura93
1 year, 5 months ago
The answer should be B. In this case, you can create a rule that allows access to the Cloud Storage bucket only from IP addresses based in Canada. This will ensure that only employees who are based in Canada will be able to access the bucket. D is not the most effective way to restrict access to the bucket. If an employee is added to the group, they would be able to access the bucket, even if they are not based in Canada.
upvoted 2 times
...
MBNelo
1 year, 6 months ago
Selected Answer: D
"based", not "in"
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...