Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise protects sensitive workloads across multiple projects inside a VPC Service Controls regular service perimeter. The security engineering team must satisfy two integration and governance requirements:
gcloud CLI, strictly restricted to requests originating from verified corporate IP ranges.Which solution should the security architect implement to meet these requirements while maintaining least privilege boundary segmentation?
Configure Access Context Manager access bindings for user groups, disable the no-egress traffic policy at the project level, and allow users to authenticate using service account keys.
Create a VPC Service Controls perimeter bridge connecting the sensitive service perimeter to an unsegmented public perimeter, and grant the Project Editor role to all security administrators.
Assign the Access Context Manager Editor role, define an access level restricting source corporate IP subnets, configure perimeter ingress rules matching the access level and administrative identities, and configure perimeter ingress and egress rules that explicitly allow the Cloud Security Command Center Service Agent identity.
Deploy a centralized Next-Generation Firewall (NGFW) in a Network Virtual Appliance (NVA) and assign the Default Compute Engine Service Account to handle cross-perimeter scanning requests.
Configure Access Context Manager access bindings for user groups, disable the no-egress traffic policy at the project level, and allow users to authenticate using service account keys.
Create a VPC Service Controls perimeter bridge connecting the sensitive service perimeter to an unsegmented public perimeter, and grant the Project Editor role to all security administrators.
Assign the Access Context Manager Editor role, define an access level restricting source corporate IP subnets, configure perimeter ingress rules matching the access level and administrative identities, and configure perimeter ingress and egress rules that explicitly allow the Cloud Security Command Center Service Agent identity.
This solution uses Access Context Manager and granular VPC Service Controls ingress and egress rules to establish context-aware, directional communication channels through a secure service perimeter. By pairing contextual access levels with explicit service agent identities, the organization enforces perimeter boundary segmentation without exposing internal resources to unauthorized external entities.
gcloud CLI can only reach protected management APIs when connected from authorized corporate networks.service-org-ORGANIZATION_ID@security-center-api.iam.gserviceaccount.com) allows the scanner to operate across the boundary while denying all other unauthorized traffic.roles/accesscontextmanager.policyEditor) IAM role at the organization level to modify the perimeter's access policy and directional rules.This approach aligns with Google Cloud security best practices by avoiding perimeter bridges for asymmetric access patterns, preventing overly permissive trust zones, and maintaining explicit, auditable policy rules for service-to-service and user-to-service communications.
Deploy a centralized Next-Generation Firewall (NGFW) in a Network Virtual Appliance (NVA) and assign the Default Compute Engine Service Account to handle cross-perimeter scanning requests.