An on-premises client sends requests over a Cloud VPN and appears to come from a project that is outside a VPC Service Controls perimeter protecting a Cloud Storage bucket. Will that on-prem client be able to access the protected bucket by default?
Choose an answer
Tap an option to check your answer.
Correct answer: No — requests appearing from outside the service perimeter are blocked unless you configure an access method such as a perimeter bridge or ingress/egress rule.
Why this is the answer
VPC Service Controls perimeters protect resources by restricting access to requests originating from within the perimeter. If a request appears to come from outside the perimeter, even if it's from an on-premises network connected via Cloud VPN, it will be blocked by default. To allow such access, you must explicitly configure an access method like a perimeter bridge or ingress/egress rules. Cloud VPN traffic is not inherently treated as internal to bypass VPC Service Controls. Private Google Access facilitates private connectivity to Google services but doesn't bypass VPC Service Controls perimeter enforcement. Private Service Connect is for connecting to managed services or other VPCs, not for bypassing VPC Service Controls for on-prem access to Cloud Storage.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed