GCP PCA · Question 27 · Security Design
Your company stores highly sensitive intellectual property in a Cloud Storage bucket. You need to ensure that even if an employee with legitimate IAM permissions tries to download the data from their home network or a coffee shop, the request is denied. How should you enforce this?
Answer options:
Remove the employee's IAM permissions when they leave the office.
Implement VPC Service Controls and configure an ingress rule allowing access only from the corporate IP range.
Configure a VPC Firewall rule to block port 443 from non-corporate IPs.
Use Cloud Armor to block the employee's home IP address.
50 questions · hints · full answers · grading