Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 252 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 252

Single answerGoogle Cloud Platform

Your organization processes sensitive financial data and needs to meet strict compliance requirements. To prevent data exfiltration, you have been tasked with implementing Google Cloud security measures that restrict the movement of sensitive data outside of specific projects. Which configuration should you implement using VPC Service Controls?

  1. A

    Define a service perimeter around the projects containing sensitive data and add the required Google Cloud services.

  2. B

    Enable firewall rules to block all egress traffic from the projects containing sensitive data.

  3. C

    Use Identity and Access Management (IAM) roles to restrict access to sensitive data.

  4. D

    Configure VPC peering between the projects to isolate sensitive data traffic.

Show answer and explanation

Correct answer: A

Explanation

VPC Service Controls provide a way to define service perimeters that protect data from being exfiltrated outside of specified projects or Google Cloud services. This is particularly essential for organizations with strict compliance requirements, as it allows them to secure sensitive data at the service level. Other options, like IAM roles or firewall rules, do not provide the necessary controls to restrict data movement at the service level.

  • A. Correct.

    Correct: A service perimeter in VPC Service Controls ensures that sensitive data cannot leave the defined boundary, preventing data exfiltration for specific Google Cloud services.

  • B. Incorrect.

    Incorrect: While firewall rules can control egress traffic at the network layer, they do not provide the service-level data exfiltration protection that VPC Service Controls offer.

  • C. Incorrect.

    Incorrect: IAM roles manage user access but do not provide the necessary boundary to restrict data movement between projects or out of Google Cloud services.

  • D. Incorrect.

    Incorrect: VPC peering connects networks but does not include the security controls required to prevent data exfiltration across Google Cloud services.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam