ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 168 - Professional Cloud Security Engineer discussion

Report
Export

Your security team wants to implement a defense-in-depth approach to protect sensitive data stored in a Cloud Storage bucket. Your team has the following requirements:

The Cloud Storage bucket in Project A can only be readable from Project B.

The Cloud Storage bucket in Project A cannot be accessed from outside the network.

Data in the Cloud Storage bucket cannot be copied to an external Cloud Storage bucket.

What should the security team do?

A.
Enable domain restricted sharing in an organization policy, and enable uniform bucket-level access on the Cloud Storage bucket.
Answers
A.
Enable domain restricted sharing in an organization policy, and enable uniform bucket-level access on the Cloud Storage bucket.
B.
Enable VPC Service Controls, create a perimeter around Projects A and B. and include the Cloud Storage API in the Service Perimeter configuration.
Answers
B.
Enable VPC Service Controls, create a perimeter around Projects A and B. and include the Cloud Storage API in the Service Perimeter configuration.
C.
Enable Private Access in both Project A and B's networks with strict firewall rules that allow communication between the networks.
Answers
C.
Enable Private Access in both Project A and B's networks with strict firewall rules that allow communication between the networks.
D.
Enable VPC Peering between Project A and B's networks with strict firewall rules that allow communication between the networks.
Answers
D.
Enable VPC Peering between Project A and B's networks with strict firewall rules that allow communication between the networks.
Suggested answer: B

Explanation:

VPC Peering is between organizations not between Projects in an organization. That is Shared VPC. In this case, both projects are in same organization so having VPC Service Controls around both projects with necessary rules should be fine.

https://cloud.google.com/vpc-service-controls/docs/overview

asked 18/09/2024
Kameron Katoku
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first