Hard1 markMultiple Choice

GCP PCA · Question 30 · Domain 3: Designing for Security and Compliance

You have configured a VPC Service Controls perimeter around your production project to protect Cloud Storage. However, an external partner needs to upload files to a specific bucket within this perimeter from their own GCP project. How do you allow this?

Answer options:

A.

Remove the bucket from the perimeter.

B.

Configure an Ingress Rule on the perimeter.

C.

Configure an Egress Rule on the perimeter.

D.

Create a VPC Peering connection to the partner.

How to approach this question

Understand VPC SC Ingress vs Egress rules.

Full Answer

B.Configure an Ingress Rule on the perimeter.✓ Correct
Configure an Ingress Rule on the perimeter to allow the partner's identity to access the specific bucket.
Ingress rules in VPC Service Controls allow you to grant specific external identities access to protected resources inside the perimeter without breaking the perimeter.

Common mistakes

Confusing Ingress (inbound to perimeter) with Egress (outbound from perimeter).

Practice the full GCP Professional Cloud Architect Practice Exam 2

50 questions · hints · full answers · grading

More questions from this exam