Restrict access to a Cloud Storage bucket so only instances in VPCs under project XYZ can access it. What do you implement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a VPC Service Controls perimeter around project XYZ and include storage.googleapis.com as a restricted service..
Why this is the answer
VPC Service Controls creates a security perimeter around your Google Cloud resources, including Cloud Storage, to mitigate data exfiltration risks. By creating a perimeter around project XYZ and restricting storage.googleapis.com, you ensure that only resources within that perimeter (like instances in VPCs under project XYZ) can access the specified Cloud Storage buckets. Enabling Private Google Access allows private IP access but doesn't restrict access to specific projects or perimeters. Cloud Storage project-level ACLs manage access for principals (users, service accounts) but don't restrict network access based on VPCs. Private Service Connect is for consuming managed services privately, not for restricting access to Cloud Storage buckets based on project VPCs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed