Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is designing an automated data ingestion pipeline where external applications running on an on-premises platform need to upload analytics datasets into Google Cloud resources. The security architecture team has established two strict compliance requirements:
Which architecture should you implement to satisfy these security requirements?
Workload Identity Federation is an identity mechanism that allows workloads running outside Google Cloud (such as on-premises environments or other cloud platforms) to impersonate IAM service accounts and obtain short-lived OAuth 2.0 access tokens using industry-standard protocols like OpenID Connect (OIDC) or SAML 2.0. VPC Service Controls is a resource-centric security perimeter capability that defines boundaries around Google Cloud services and APIs to mitigate data exfiltration risks and block unauthorized access from outside trusted perimeters.
Combining Workload Identity Federation with VPC Service Controls is the recommended architecture for enterprise integrations. It directly resolves the dual challenge of eliminating static credential storage at the identity layer while establishing strict perimeter boundaries that prevent data exfiltration at the network and API layers.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.