Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise is deploying proprietary machine learning models for online inference on Vertex AI. The security team requires a multi-layered security architecture that accomplishes the following:
Which architecture should you implement to satisfy these security requirements?
Place the Vertex AI and data storage projects within a common VPC Service Controls perimeter, encrypt model artifacts with CMEK managed in a dedicated Cloud KMS project granting the CryptoKey Encrypter/Decrypter role to service agents, use custom service accounts with least privilege IAM roles for endpoints, and enable Data Access audit logs.
Deploy Vertex AI endpoints in a shared development project, attach Google Cloud Armor security policies directly to the Vertex AI prediction endpoints, protect data with Google default encryption, and configure Cloud Monitoring metric alerts for prediction volume.
Deploy Identity-Aware Proxy (IAP) in front of public Vertex AI endpoints, perform client-side symmetric encryption on all model artifacts prior to uploading them to Cloud Storage, and route all container egress traffic through Cloud NAT.
Configure IAM condition bindings restricted by corporate IP ranges on Vertex AI endpoints, configure Customer-Supplied Encryption Keys (CSEK) on the Vertex AI model registry, and deploy standard VPC firewall ingress rules to block unauthorized inference traffic.
Place the Vertex AI and data storage projects within a common VPC Service Controls perimeter, encrypt model artifacts with CMEK managed in a dedicated Cloud KMS project granting the CryptoKey Encrypter/Decrypter role to service agents, use custom service accounts with least privilege IAM roles for endpoints, and enable Data Access audit logs.
This architecture represents Google Cloud's recommended end-to-end security design for enterprise AI workloads. It combines perimeter security via VPC Service Controls, cryptographic governance using Customer-Managed Encryption Keys (CMEK), granular identity governance using Identity and Access Management (IAM) with custom service accounts, and operational visibility through Cloud Audit Logs.
roles/cloudkms.cryptoKeyEncrypterDecrypter role specifically to the Vertex AI and Cloud Storage service agents ensures automated service-level cryptographic operations without granting developers direct key manipulation privileges.This solution implements deep defense across network, identity, cryptographic, and operational logging layers. It strictly adheres to enterprise separation of duties and standard Google Cloud reference architectures for sensitive AI deployments.
Deploy Vertex AI endpoints in a shared development project, attach Google Cloud Armor security policies directly to the Vertex AI prediction endpoints, protect data with Google default encryption, and configure Cloud Monitoring metric alerts for prediction volume.
Deploy Identity-Aware Proxy (IAP) in front of public Vertex AI endpoints, perform client-side symmetric encryption on all model artifacts prior to uploading them to Cloud Storage, and route all container egress traffic through Cloud NAT.
Configure IAM condition bindings restricted by corporate IP ranges on Vertex AI endpoints, configure Customer-Supplied Encryption Keys (CSEK) on the Vertex AI model registry, and deploy standard VPC firewall ingress rules to block unauthorized inference traffic.