Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 56 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 56

Select 3Google Cloud Platform

You are designing a secure architecture for a healthcare organization that uses Google Cloud. The organization stores sensitive data in Cloud Storage and BigQuery. To ensure compliance with data security requirements, you need to prevent data exfiltration to unauthorized networks or services while allowing internal teams to work with the data. How should you configure VPC Service Controls to meet these requirements?

  1. A

    Define a service perimeter around Cloud Storage and BigQuery to restrict access to these resources from outside the perimeter.

  2. B

    Enable private Google access for the VPC to allow access to Google APIs and services from internal networks.

  3. C

    Use Cloud VPN to connect to external partners and whitelist their IP ranges in the service perimeter.

  4. D

    Configure access levels to allow specific groups of users to securely access the data from trusted networks or devices.

  5. E

    Disable all external access to Google Cloud services by removing public IPs from all VMs in the VPC.

Show answer and explanation

Correct answers: A, B, D

Explanation

VPC Service Controls help organizations protect their sensitive data by creating a security boundary around Google Cloud services such as Cloud Storage and BigQuery. By defining a service perimeter and enabling private Google access, you can ensure that these services are only accessible from within the VPC. Additionally, configuring access levels provides fine-grained control over access permissions, ensuring that only authorized users or devices can interact with the data. These methods balance security with usability, preventing data exfiltration while enabling internal workflows.

  • A. Correct.

    Correct: Defining a service perimeter around Cloud Storage and BigQuery ensures that these services can only be accessed from within the perimeter, preventing unauthorized external access.

  • B. Correct.

    Correct: Enabling private Google access is required to allow resources within the VPC to securely access Google services and APIs without exposing them to the internet.

  • C. Incorrect.

    Incorrect: Cloud VPN is not directly related to configuring VPC Service Controls, and whitelisting external IP ranges could introduce security risks.

  • D. Correct.

    Correct: Access levels in VPC Service Controls allow for fine-grained control over who can access the data, enabling secure access for specific users or groups from trusted environments.

  • E. Incorrect.

    Incorrect: Disabling all external access is overly restrictive and not practical for enabling secure collaboration or access to necessary Google Cloud services.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam