professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise publishes shared data listings using BigQuery Analytics Hub. A subscriber team in caller project analytics-subscriber (Project R) has subscribed to a listing and provisioned a linked dataset in project subscriber-warehouse (Project L). The underlying shared dataset contains views in project subscriber-warehouse that reference underlying base tables hosted in project source-storage (Project V).
Each project resides in a separate, isolated VPC Service Controls perimeter. Queries executed by analysts in Project R against the linked dataset views are currently failing due to perimeter violations.
Which VPC Service Controls ingress and egress rules must you configure to allow users in Project R to query the views while maintaining perimeter security across all projects?
Configure egress rules in Project R for Projects L and V; configure an ingress rule in Project L for Project R and an egress rule for Project V; and configure an egress rule in Project V for Project L and an ingress rule for Project R.
Configure an ingress rule in Project V for Project L and an egress rule in Project L for Project V, without modifying perimeter rules in caller Project R.
Configure egress rules in Project R for Project L only, and configure an ingress rule in Project L for Project R only.
Configure ingress and egress rules between Project R and Project E (the data exchange host project) only, while leaving Project L and Project V within default perimeter blocking rules.
Configure egress rules in Project R for Projects L and V; configure an ingress rule in Project L for Project R and an egress rule for Project V; and configure an egress rule in Project V for Project L and an ingress rule for Project R.
VPC Service Controls allows organizations to establish fine-grained security perimeters around Google Cloud resources, including BigQuery Analytics Hub, to prevent data exfiltration. When BigQuery queries span multiple perimeters across caller projects, linked datasets, and underlying source datasets containing base tables, specific directional ingress and egress rules must be defined to bridge perimeter boundaries.
When an analyst queries a view in a linked dataset where the view, caller, and base tables are distributed across separate perimeters:
This configuration accurately aligns with the multi-perimeter architecture rules required by Analytics Hub when views and underlying base tables reside in separate projects and service perimeters.
Configure an ingress rule in Project V for Project L and an egress rule in Project L for Project V, without modifying perimeter rules in caller Project R.
Configure egress rules in Project R for Project L only, and configure an ingress rule in Project L for Project R only.
Configure ingress and egress rules between Project R and Project E (the data exchange host project) only, while leaving Project L and Project V within default perimeter blocking rules.