Analysts have IAM read access to sensitive Cloud Storage buckets. Prevent analysts from accessing bucket data from outside the office network. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a VPC Service Controls perimeter that includes the projects with the buckets and create an access level restricted to the office network CIDR..
Why this is the answer
The correct solution is to create a VPC Service Controls perimeter with an access level restricted to the office network CIDR. VPC Service Controls create a security perimeter around your Google Cloud resources, preventing data exfiltration and unauthorized access. By defining an access level based on the office network's IP range, you ensure that only requests originating from within that network can access the sensitive Cloud Storage buckets, even if the user has valid IAM permissions. Creating a firewall rule on the VPC network is insufficient because Cloud Storage access is typically over public APIs, not directly through VPC instances. Cloud Functions for scheduled IAM changes are complex, error-prone, and don't prevent access from outside the office during business hours. Cloud VPN with Private Google Access is for connecting on-premises hosts to Google Cloud privately, not for restricting access to Google Cloud services based on source IP.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed