Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is designing a Cardholder Data Environment (CDE) on Google Cloud to meet stringent PCI-DSS and FedRAMP network segmentation and perimeter defense mandates. The architecture deploys a Shared VPC host project for centralized network management alongside multiple service projects hosting compute workloads, Cloud Build private pools, and Cloud Storage buckets containing sensitive cardholder data.
Which architectural requirement must be implemented to enforce the VPC Service Controls boundary across this infrastructure without breaking communication?
VPC Service Controls allows enterprises to establish a secure, logical boundary around Google-managed resources and APIs to mitigate data exfiltration risks. When paired with a Shared VPC architecture, VPC Service Controls perimeter configuration requires that both the host project (which provides the underlying network infrastructure and subnets) and all attached service projects (which host the compute instances and application resources) reside within the exact same service perimeter.
storage.googleapis.com and cloudbuild.googleapis.com ensures that only authorized identities and networks inside the perimeter can access those service endpoints.Placing both the host project and service projects inside the same service perimeter aligns with Google Cloud security best practices for Shared VPC and prevents broken cross-project API routing, ensuring uninterrupted compliance enforcement.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.