An organization needs to ensure that authorized users cannot copy sensitive data stored in Cloud Storage to external, unauthorized Google Cloud projects. Which Google Cloud security feature should be configured to establish this security boundary?
- VPC Service Controls service perimeters around the projectCevap
- BFine-grained Identity and Access Management (IAM) custom roles restricting bucket permissions
- CTransitive VPC Network Peering to route all service traffic through a central inspection project
- DPrimitive IAM Viewer roles on the project level instead of object-level permissions
Cevap
VPC Service Controls service perimeters around the project
VPC Service Controls allow security administrators to define perimeter boundaries around Google Cloud resources to prevent sensitive data from being moved outside controlled network environments.
Adım Adım Çözüm
Anahtar Kavram
VPC Service Controls for Data Exfiltration Prevention
Tahmini Süre:1m 0s