Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise stores proprietary financial analytics data inside private Cloud Storage buckets located in a dedicated project. The organization has two key security requirements:
Which architectural strategy should you implement to satisfy both requirements?
Enclose the Cloud Storage project within a VPC Service Controls service perimeter, and generate Signed URLs with short expiration times for external auditors to access specific objects.
Enable Data Security Posture Management (DSPM) in Security Command Center, and attach Object Lifecycle Management rules to auto-delete objects after 24 hours.
Configure uniform bucket-level access on the Cloud Storage buckets, and apply Cloud Armor security policies directly to the bucket storage endpoints.
Deploy Private Service Connect endpoints in a Shared VPC host project, and assign the roles/storage.objectViewer IAM role to a public Google Group containing the external auditors.
Enclose the Cloud Storage project within a VPC Service Controls service perimeter, and generate Signed URLs with short expiration times for external auditors to access specific objects.
VPC Service Controls allows organizations to create secure network and service perimeters around sensitive Google Cloud resources, such as Cloud Storage, preventing multi-tenant service communication from crossing perimeter boundaries. Signed URLs provide time-limited, cryptographically signed access to specific Cloud Storage objects without requiring the recipient to possess Google Cloud Identity credentials or direct Identity and Access Management (IAM) roles.
GET requests against designated files for a predetermined lifespan (e.g., 60 minutes). This avoids persistent IAM role assignments or tenant account provisioning.This architecture pairs foundational perimeter defense against data exfiltration with temporary, zero-footprint delegation of access to external partners.
Enable Data Security Posture Management (DSPM) in Security Command Center, and attach Object Lifecycle Management rules to auto-delete objects after 24 hours.
Configure uniform bucket-level access on the Cloud Storage buckets, and apply Cloud Armor security policies directly to the bucket storage endpoints.
Deploy Private Service Connect endpoints in a Shared VPC host project, and assign the roles/storage.objectViewer IAM role to a public Google Group containing the external auditors.