Question 152 of 315
Single answerYour company has a Google Cloud project that uses BigQuery for data warehousing. They have a VPN tunnel between the on-premises environment and Google
Cloud that is configured with Cloud VPN. The security team wants to avoid data exfiltration by malicious insiders, compromised code, and accidental oversharing.
What should they do?
AConfigure Private Google Access for on-premises only.
BPerform the following tasks: 1. Create a service account. 2. Give the BigQuery JobUser role and Storage Reader role to the service account. 3. Remove all other IAM access from the project.
✓CConfigure VPC Service Controls and configure Private Google Access.
DConfigure Private Google Access.
✓
Correct Answer: C
Configure VPC Service Controls and configure Private Google Access.
▥
Explanation
The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of Google certification topics.