Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organization is designing a separation of duties (SoD) framework across multiple Google Cloud projects protected by VPC Service Controls (VPC SC) perimeters. The security team wants to define role-based ingress and egress rules to allow developers to perform specific operations across perimeters while strictly isolating administrative privilege assignment and preventing unauthorized cross-perimeter IAM modifications.
Which constraint or limitation regarding role-based ingress and egress rules must the security team account for when architecting this separation of duties model?
VPC Service Controls allows administrators to define ingress and egress rules using IAM roles to restrict or permit context-aware API calls across service perimeters. This ensures that only principals possessing specific predefined or custom roles can access protected resources across network and perimeter boundaries.
To protect the integrity of the authorization boundary and prevent privilege escalation across perimeters, Google Cloud enforces an architectural boundary restriction:
setIamPolicy API requests (such as /resource-manager/reference/rest/v3/projects/setIamPolicy) across perimeter boundaries.Understanding this fundamental limitation allows security architects to properly separate day-to-day role-based data operations from identity policy governance, ensuring that IAM policy modifications require direct, tightly controlled administrative channels rather than ambient role-based cross-perimeter rules.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.