Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your enterprise has acquired a subsidiary operating under a separate Google Cloud organization. Workloads running in Project A (within Organization A) require private access to Cloud Storage buckets hosted in Project B (within Organization B).
Both organizations enforce strict data exfiltration defenses using VPC Service Controls perimeters around their respective projects. You must establish private, policy-governed communication between these disparate organizations without compromising perimeter boundaries.
What should you do?
Add Project A into Organization B's existing service perimeter and grant the Storage Object Viewer role to Project A's service account.
Configure an egress rule in Organization A's service perimeter and an ingress rule in Organization B's service perimeter to allow specific identities, methods, and resources.
Configure Shared VPC across the organizations by designating Project B as the host project and attaching Project A as a service project.
Establish VPC Network Peering between the VPC in Project A and the VPC in Project B, and disable VPC Service Controls on Project B.
Add Project A into Organization B's existing service perimeter and grant the Storage Object Viewer role to Project A's service account.
Configure an egress rule in Organization A's service perimeter and an ingress rule in Organization B's service perimeter to allow specific identities, methods, and resources.
VPC Service Controls ingress and egress rules provide secure, bidirectional data exchange pathways across distinct service perimeters and separate Google Cloud organizations without dismantling existing security perimeters.
Because a service perimeter cannot span across multiple Google Cloud organizations, configuring directional ingress and egress rules is the standard, secure mechanism to enable authorized cross-organization data exchange while preventing unauthorized data exfiltration.
Configure Shared VPC across the organizations by designating Project B as the host project and attaching Project A as a service project.
Establish VPC Network Peering between the VPC in Project A and the VPC in Project B, and disable VPC Service Controls on Project B.