List of questions
Related questions
Question 192 - Professional Cloud Security Engineer discussion
You manage one of your organization's Google Cloud projects (Project A). AVPC Service Control (SC) perimeter is blocking API access requests to this project including Pub/Sub. A resource running under a service account in another project (Project B) needs to collect messages from a Pub/Sub topic in your project Project B is not included in a VPC SC perimeter. You need to provide access from Project B to the Pub/Sub topic in Project A using the principle of least
Privilege.
What should you do?
A.
Configure an ingress policy for the perimeter in Project A and allow access for the service account in Project B to collect messages.
B.
Create an access level that allows a developer in Project B to subscribe to the Pub/Sub topic that is located in Project A.
C.
Create a perimeter bridge between Project A and Project B to allow the required communication between both projects.
D.
Remove the Pub/Sub API from the list of restricted services in the perimeter configuration for Project A.
Your answer:
0 comments
Sorted by
Leave a comment first