Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 140 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 140

Single answerGoogle Cloud Platform

A company wants to restrict access to its internal Google Cloud web application so that only employees accessing it from the corporate office network or using company-managed devices can connect. Which configuration step in Access Context Manager is required to achieve this?

  1. A

    Create an access level with conditions based on IP subnet and device attributes.

  2. B

    Assign roles/owner IAM role to the users accessing the application.

  3. C

    Enable VPC Service Controls for the application.

  4. D

    Create a custom IAM role with permissions to enforce the required restrictions.

Show answer and explanation

Correct answer: A

Explanation

Access Context Manager allows you to define fine-grained access policies using access levels. By specifying conditions such as IP subnets (corporate office network) and device attributes (managed devices), you can ensure that only users meeting these criteria can access the web application. Other options like IAM roles or VPC Service Controls do not fulfill the scenario's requirement.

  • A. Correct.

    Correct: Access Context Manager allows you to define access levels with conditions such as IP subnets and device attributes. This is the exact requirement in the scenario.

  • B. Incorrect.

    Incorrect: Assigning roles like roles/owner is unrelated to configuring access restrictions based on IP or devices. IAM roles define permissions but do not control network or device-based access.

  • C. Incorrect.

    Incorrect: Enabling VPC Service Controls secures data within services but does not handle access restrictions based on user location or device. This is not sufficient for the given scenario.

  • D. Incorrect.

    Incorrect: While you can create custom IAM roles, these roles are used to grant granular permissions. They cannot enforce IP or device-based access restrictions.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam