Google Professional Cloud Developer exam dumps

Google Professional Cloud Developer practice question 157 of 481

Professional Cloud Developer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Developer Question 157

Single answerGoogle Cloud Platform

You are developing an application that stores sensitive files in a Google Cloud Storage bucket. To comply with security requirements, you need to grant temporary read access to these files for an external client. Which approach should you use to meet this requirement?

  1. A

    Use Signed URLs to generate a time-limited access link for the client.

  2. B

    Set a lifecycle policy on the bucket to automatically delete objects after a specific duration.

  3. C

    Grant the client the 'Storage Object Viewer' role at the bucket level and remove the role manually after access is no longer needed.

  4. D

    Use a VPC Service Controls perimeter to restrict access to the bucket for a specific duration.

Show answer and explanation

Correct answer: A

Explanation

The correct solution for granting time-limited access to specific objects in a Cloud Storage bucket is to use Signed URLs. Signed URLs allow you to create a URL with a specified expiration time, providing secure and temporary access to objects without the need to manage IAM roles or permissions.

  • A. Correct.

    Correct. Signed URLs allow you to generate a time-limited access link to a specific object in a Cloud Storage bucket. It is the appropriate solution for granting temporary access to specific objects.

  • B. Incorrect.

    Incorrect. Lifecycle policies are used to manage the lifecycle of objects in a bucket, such as deleting them after a certain period, but they do not provide temporary access to users.

  • C. Incorrect.

    Incorrect. Granting a role at the bucket level is not time-limited, and manually removing the role is error-prone and not recommended for temporary access.

  • D. Incorrect.

    Incorrect. VPC Service Controls are used to define security perimeters around resources to restrict access, but they are not designed for granting temporary, object-specific access.

Timed practice exam

Take a Google Professional Cloud Developer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam