Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise protects sensitive workloads across multiple projects inside a VPC Service Controls regular service perimeter. The security engineering team must satisfy two integration and governance requirements:
gcloud CLI, strictly restricted to requests originating from verified corporate IP ranges.Which solution should the security architect implement to meet these requirements while maintaining least privilege boundary segmentation?
This solution uses Access Context Manager and granular VPC Service Controls ingress and egress rules to establish context-aware, directional communication channels through a secure service perimeter. By pairing contextual access levels with explicit service agent identities, the organization enforces perimeter boundary segmentation without exposing internal resources to unauthorized external entities.
gcloud CLI can only reach protected management APIs when connected from authorized corporate networks.service-org-ORGANIZATION_ID@security-center-api.iam.gserviceaccount.com) allows the scanner to operate across the boundary while denying all other unauthorized traffic.roles/accesscontextmanager.policyEditor) IAM role at the organization level to modify the perimeter's access policy and directional rules.This approach aligns with Google Cloud security best practices by avoiding perimeter bridges for asymmetric access patterns, preventing overly permissive trust zones, and maintaining explicit, auditable policy rules for service-to-service and user-to-service communications.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.