Professional Cloud Security Engineer Exam QuestionsBrowse all questions from this exam

Professional Cloud Security Engineer Exam - Question 184


You have a highly sensitive BigQuery workload that contains personally identifiable information (PII) that you want to ensure is not accessible from the internet. To prevent data exfiltration, only requests from authorized IP addresses are allowed to query your BigQuery tables.

What should you do?

Show Answer
Correct Answer: A

To ensure that only requests from authorized IP addresses can query your BigQuery tables and prevent data exfiltration, using a service perimeter and creating an access level based on the authorized source IP address as the condition is the best approach. This allows you to create a boundary that controls access to Google Cloud resources for services within the same perimeter, ensuring sensitive data is not accessible from the internet.

Discussion

6 comments
Sign in to comment
pfilourencoOption: A
Aug 4, 2023

A is the correct.

cyberpunk21Option: A
Aug 24, 2023

Option A is correct

Sanjana2020Option: A
Aug 2, 2023

I think its A.

i_am_robotOption: A
Dec 17, 2023

The best option would be A. Use service perimeter and create an access level based on the authorized source IP address as the condition. This approach allows you to create a boundary that controls access to Google Cloud resources for services within the same perimeter. By creating an access level based on the authorized source IP address as the condition, you can ensure that only requests from authorized IP addresses are allowed to query your BigQuery tables. This effectively prevents data exfiltration and ensures that your sensitive BigQuery workload is not accessible from the internet.

b6f53d8Option: A
Feb 3, 2024

A and B will work, but A in better in my opinion

pfilourencoOption: A
Jun 12, 2024

A is the correct one.