Prevent data exfiltration from BigQuery over a Cloud VPN connection to on‑premises; enforce controls against insider threats and accidental sharing.
Choose an answer
Tap an option to check your answer.
Correct answer: Configure VPC Service Controls for the project perimeter and enable Private Google Access..
Why this is the answer
VPC Service Controls create a security perimeter around your BigQuery project, preventing data exfiltration by restricting access to authorized networks and services. This directly addresses the need to prevent data from leaving BigQuery over the VPN. Enabling Private Google Access ensures that authorized on-premises systems can still access BigQuery privately within the perimeter, without traversing the public internet, which is essential for the Cloud VPN connection. "Configure Private Google Access for on-premises only" and "Configure Private Google Access" are insufficient as they only provide private connectivity, not data exfiltration prevention. "Create a service account, grant BigQuery JobUser and Storage Reader roles to that account, and remove all other IAM access in the project" focuses on identity and access management, which is important but doesn't create a network perimeter to prevent exfiltration.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed