Question 300 of 318
Single answer• For the service perimeter, specify the two new projects as “Resources to protect†in the service perimeter configuration.
• Set “Restricted services†to “all services,†set “VPC accessible services†to “Selected services,†and specify only BigQuery and Cloud Storage under “Selected services.â€
• Create an Access Context Manager access level with an “IP Subnetworks†attribute condition set to the US-based corporate IP range.
• Enable the “Restrict Resource Service Usage†organization policy at the new folder level with an “Allow†policy type and set both “storage.googleapis.com†and “bigquery.googleapis.com†under “Custom values.â€
• Specify the two new projects as “Resources to protect†in the service perimeter configuration.
• Set “Restricted services†to “all services,†set “VPC accessible services†to “Selected services,†and specify only BigQuery and Cloud Storage.
• Edit the existing access level to add a “Geographic locations†condition set to “US.â€
• Configure the VPC firewall policies within the new projects to only allow connections from the on-premises IP address range.
• Enable the Restrict Resource Service Usage organization policy on the new folder with an “Allow†policy type, and set both “storage.googleapis.com†and “bigquery.googleapis.com†under “Custom values.â€
• Edit the organization-level access policy and add the new folder under “Select resources to include in the policy.â€<br> • Specify the two new projects as “Resources to protect†in the service perimeter configuration.<br> • Set “Restricted services†to “all services,†set “VPC accessible services†to “Selected services,†and specify only BigQuery and Cloud Storage.<br> • Edit the existing access level to add a “Geographic locations†condition set to “US.â€
The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of Google certification topics.