Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise maintains two distinct regular VPC Service Controls perimeters: Perimeter-A for core internal workloads and Perimeter-B for departmental data storage. A centralized processing workload in a project within Perimeter-A requires bidirectional API communication and data exchange with Cloud Storage buckets located in a project protected by Perimeter-B.
The organization's governance rules prohibit merging the perimeters or modifying the projects assigned to each perimeter boundary.
Which solution should the security engineer implement to enable communication between the two projects?
Create a perimeter bridge that includes the specific project from Perimeter-A and the specific project from Perimeter-B.
Configure an Access Level on Perimeter-A specifying the internal VPC subnet IP address ranges of the project in Perimeter-B.
Add the project from Perimeter-B directly into Perimeter-A so that both projects share a single regular service perimeter.
Enable VPC Accessible Services on Perimeter-A and add the Cloud Storage API (storage.googleapis.com) to the allowed list.
Create a perimeter bridge that includes the specific project from Perimeter-A and the specific project from Perimeter-B.
A perimeter bridge in Access Context Manager allows projects enclosed in distinct regular service perimeters to communicate and share protected Google Cloud resources without merging or altering the membership of the underlying perimeters.
Perimeter-A and the project in Perimeter-B, allowing services within those specific projects to exchange data directly while keeping perimeter boundaries intact.Perimeter-A and Perimeter-B that are not listed in the bridge cannot access each other, preserving isolation across security zones.Perimeter bridges allow targeted inter-perimeter access without violating the architectural rule that a project can belong to only one regular perimeter, and without exposing the rest of either perimeter's projects to unnecessary lateral communication.
Configure an Access Level on Perimeter-A specifying the internal VPC subnet IP address ranges of the project in Perimeter-B.
Add the project from Perimeter-B directly into Perimeter-A so that both projects share a single regular service perimeter.
Enable VPC Accessible Services on Perimeter-A and add the Cloud Storage API (storage.googleapis.com) to the allowed list.