Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 524 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 524

Single answerGoogle Cloud Platform

You are tasked with setting up temporary access to a large file stored in a Google Cloud Storage bucket for a third-party service. The file contains sensitive data, and you want to ensure that access is both secure and time-limited. How can you achieve this using Signed URLs?

  1. A

    Generate a Signed URL with a specific expiration time and share it with the third-party service.

  2. B

    Make the bucket publicly accessible and share the public link with the third-party service.

  3. C

    Configure a VPC Service Controls perimeter around the bucket and grant the third-party service access.

  4. D

    Provide the third-party service with your Google Cloud Service Account credentials to access the file directly.

Show answer and explanation

Correct answer: A

Explanation

Signed URLs are an effective way to grant temporary, secure access to specific objects in a Google Cloud Storage bucket. By configuring an expiration time, you ensure that the access is limited to the required duration, and by sharing the Signed URL, you avoid exposing broader access credentials or permissions.

  • A. Correct.

    This is the correct approach. A Signed URL allows secure, time-limited access to a specific object in a Google Cloud Storage bucket without exposing broader permissions. You can configure the expiration time to ensure the URL is valid only for the required duration.

  • B. Incorrect.

    Making the bucket publicly accessible compromises the security of the sensitive data as it allows anyone with the link to access the file without restrictions.

  • C. Incorrect.

    VPC Service Controls enhance security by restricting access to resources within a defined perimeter, but they are not designed for sharing temporary access with third-party services.

  • D. Incorrect.

    Sharing your Google Cloud Service Account credentials violates security best practices and is not recommended for granting temporary access.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam