Courseiva
Security →hardMultiple Choice

CV0-004 Security Practice Question

A multinational company uses Google Cloud and needs to ensure that its data cannot be exfiltrated to unauthorized networks even if an attacker obtains valid IAM credentials. The security team wants to define a boundary around specific projects and restrict access to only approved VPC networks and services. Which GCP feature should they implement?

⚠ Common exam trap

The trap here is assuming that IAM and firewall rules are sufficient to stop exfiltration, when an attacker with valid credentials can use service APIs that bypass VPC-level controls unless a service perimeter is in place.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Service Controls

VPC Service Controls establish a security perimeter around Google Cloud projects and services, restricting access to authorized VPC networks and preventing data exfiltration even when IAM credentials are compromised. The other options protect application access, VM egress, or edge traffic, none of which create the service-level boundary needed to stop API-based data movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC firewall rules with egress deny

    Why it's wrong here

    VPC firewall rules can restrict egress traffic from VM instances, but they do not protect Google Cloud managed services like Cloud Storage or BigQuery from API-level exfiltration. An attacker with valid credentials could use APIs to move data without traversing the VPC, so firewall rules alone cannot enforce the required boundary.

  • ✗

    Cloud Armor security policies

    Why it's wrong here

    Cloud Armor protects external HTTP(S) load-balanced applications from DDoS and web attacks. It does not create a perimeter around Google Cloud services or prevent data exfiltration via APIs. It operates at the edge for inbound traffic, not for controlling outbound access to services, so it does not satisfy the requirement.

  • ✓

    VPC Service Controls

    Why this is correct

    VPC Service Controls create a service perimeter around Google Cloud projects and resources, restricting access to only approved VPC networks and preventing data exfiltration even with valid credentials. This directly addresses the requirement to block exfiltration despite compromised IAM credentials, because the perimeter enforces context-aware access independent of IAM permissions.

  • ✗

    Cloud Identity-Aware Proxy (IAP)

    Why it's wrong here

    IAP controls access to applications based on identity and context, but it does not create a data boundary around Google Cloud services. An attacker with valid IAM credentials and network access could still copy data to an external bucket. IAP protects application access, not service-level data exfiltration, so it does not meet the boundary requirement.

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.