You must share a sensitive object in Cloud Storage with an external company that has no Google account and ensure access is removed after four hours. Which approach is most secure and requires the fewest steps?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a signed URL with a four-hour expiration and share it..
Why this is the answer
Creating a signed URL with a four-hour expiration is the most secure and efficient method. Signed URLs grant temporary, time-limited access to specific objects without requiring Google accounts or making the object publicly accessible. This directly addresses the need for secure, temporary access for an external company without a Google account. Making the object public is insecure as anyone could access it, and lifecycle management deletes the object, not just access. Configuring the bucket as a static website still makes the object publicly accessible, which is insecure, and deleting the object removes it permanently. Creating a new bucket and copying the object is overly complex and resource-intensive for temporary access to a single object.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed