Development and External teams both have viewer IAM on a Visualization folder. Development should read Cloud Storage and BigQuery; External should read only BigQuery. What change enforces this?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a VPC Service Controls perimeter containing both projects and Cloud Storage as a restricted API; add Development Team users to the perimeter's Access Level..
Why this is the answer
The correct answer enforces the requirement by restricting Cloud Storage access for the External Team while allowing it for the Development Team. VPC Service Controls create a security perimeter around resources, preventing data exfiltration. By restricting Cloud Storage within this perimeter and only allowing Development Team users through an Access Level, External Team users, who are outside this Access Level, lose Cloud Storage access while retaining BigQuery access. Incorrect options: Removing Cloud Storage IAM for the External Team on acme-raw-data would prevent both teams from accessing Cloud Storage if they both inherit permissions from the project, or it wouldn't differentiate if permissions are set at a lower level. VPC firewall rules control network traffic, not access to specific Google Cloud services like Cloud Storage or BigQuery based on user identity. Restricting BigQuery as an API would prevent both teams from accessing BigQuery, which violates the requirement for both teams to read BigQuery.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed