Google Professional Cloud Architect (PR000213) Exam - Topic 11 Question 16 Discussion
Your company has sensitive data in Cloud Storage buckets. Data analysts have Identity Access Management (IAM) permissions to read the buckets. You want to prevent data analysts from retrieving the data in the buckets from outside the office network. What should you do?
A) 1. Create a VPC Service Controls perimeter that includes the projects with the buckets.
2. Create an access level with the CIDR of the office network.
B) 1. Create a firewall rule for all instances in the Virtual Private Cloud (VPC) network for source range.
2. Use the Classless Inter-domain Routing (CIDR) of the office network.
C) 1. Create a Cloud Function to remove IAM permissions from the buckets, and another Cloud Function to add IAM permissions to the buckets.
2. Schedule the Cloud Functions with Cloud Scheduler to add permissions at the start of business and remove permissions at the end of business.
D) 1. Create a Cloud VPN to the office network.
2. Configure Private Google Access for on-premises hosts.
Dorothea
7 months agoGail
7 months agoVirgilio
8 months agoHoa
8 months agoBrock
8 months agoLenora
8 months agoQueenie
8 months agoTeresita
8 months agoSalena
8 months agoElenora
8 months agoLilli
8 months agoGenevieve
8 months ago