Single project with multiple VPCs. Secure API access to Cloud Storage and BigQuery, allowing access only from corporate public networks. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a VPC Service Controls perimeter for your project with an access context policy that allows your corporate public network IP ranges..
Why this is the answer
VPC Service Controls protect sensitive data in Google Cloud by creating security perimeters around resources and restricting data movement. By creating a perimeter for the project and an access context policy allowing only corporate public IP ranges, you ensure that Cloud Storage and BigQuery can only be accessed from authorized networks, regardless of the VPCs within the project. The other options are less effective: An access context policy alone, without a VPC Service Controls perimeter, won't enforce the restriction on API access to Cloud Storage and BigQuery. Firewall rules operate at the network level and cannot control access to Google-managed services like Cloud Storage and BigQuery APIs. Creating a perimeter for each VPC is unnecessary and overly complex; a single project-level perimeter is sufficient to protect the services within that project.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed