Courseiva
hardMultiple Choice

Google ACE Practice Question: Your organization uses VPC Service Controls to…

Your organization uses VPC Service Controls to protect BigQuery and Cloud Storage. A data pipeline service account needs to read from a protected Cloud Storage bucket and write results to a protected BigQuery dataset. Both resources are in the same perimeter. The service account is outside the perimeter (it runs in a Cloud Run service in a different project). How do you grant the pipeline access?

⚠ Common exam trap

Google Cloud often tests the misconception that IAM roles can override VPC Service Controls, but the trap here is that VPC-SC operates independently of IAM and requires explicit ingress or egress rules for cross-perimeter access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Ingress Rule in the VPC-SC perimeter that allows the service account from the external project to access the specific BigQuery and Storage resources.

VPC Service Controls (VPC-SC) allow you to define ingress rules that grant access to protected resources from identities outside the perimeter. In this scenario, the service account running in Cloud Run is outside the perimeter, so an ingress rule must explicitly permit that service account to access the specific BigQuery dataset and Cloud Storage bucket. This approach maintains the security boundary while enabling the required data pipeline access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add the Cloud Run project to the VPC Service Controls perimeter.

    Why it's wrong here

    Adding the Cloud Run project to the VPC Service Controls perimeter extends the boundary to encompass every identity and resource within that project, so any service account or user in the project could access the protected BigQuery and Storage resources, not just the specific Cloud Run service. This violates least privilege because the rule grants project-wide access rather than scoping to a single service identity. VPC-SC supports per-service ingress rules specifically to avoid this broad blast radius, making project-level inclusion a blunt and risky configuration.

  • ✓

    Create an Ingress Rule in the VPC-SC perimeter that allows the service account from the external project to access the specific BigQuery and Storage resources.

    Why this is correct

    An ingress rule in VPC Service Controls is the precise mechanism for allowing an external identity, such as the Cloud Run service account, to access protected resources inside the perimeter. The rule specifies the source identity (the service account), the source project (the Cloud Run project), and the exact target resources (particular BigQuery datasets and Storage buckets), limiting exposure to only what the service genuinely needs. This is the least-privileged and context-aware approach, and it is the only option that correctly addresses the boundary enforcement.

  • ✗

    Grant the service account `roles/bigquery.admin` and `roles/storage.admin` to bypass the perimeter restrictions.

    Why it's wrong here

    VPC Service Controls is enforced before IAM authorization: if the request source is not allowed by the perimeter, the request is denied at the context-aware layer regardless of the roles assigned to the service account. Granting roles/bigquery.admin and roles/storage.admin only expands the service account's privileges inside the perimeter, but it cannot change the external source context that VPC-SC evaluates. Additionally, these admin roles are dangerously over-privileged and would allow destructive data operations if the perimeter were ever misconfigured.

  • ✗

    Move the Cloud Run service into a VPC and set up VPC peering to the perimeter VPC.

    Why it's wrong here

    VPC peering only establishes private IP connectivity between networks; it does not place the Cloud Run service inside the VPC-SC perimeter or grant it access to perimeter-protected APIs. VPC-SC decisions are based on identity, source project, and access context — not on the network path the request traverses. Even with peering in place, the request still originates from an external project and will be denied unless a matching ingress rule explicitly permits that service account.

Go deeper

Related to this question

About these practice questions

Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.