Cloud Digital Leader Google Cloud Security Practice Question
A company wants to protect sensitive data stored in Cloud Storage from being downloaded by users outside their organization. They also need to prevent data from being copied to external projects. Which TWO services should they use? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IAM conditions with access levels
IAM conditions with access levels (A) are correct because they let you enforce context-aware access rules on Cloud Storage, such as allowing access only when the request originates from a trusted network or device, which directly addresses preventing downloads by users outside the organization. VPC Service Controls (C) are correct because they create a service perimeter around Cloud Storage that blocks data exfiltration, including preventing data from being copied to external projects outside the perimeter. Cloud DLP (B) is incorrect because it is used to discover, classify, and redact sensitive data, not to enforce access or exfiltration boundaries. Cloud KMS (D) is incorrect because it manages encryption keys and does not control who can download or copy data. Cloud Armor (E) is incorrect because it protects web applications from network-layer and application-layer attacks at the edge, not Cloud Storage data access or project boundaries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IAM conditions with access levels
Why this is correct
IAM conditions with access levels restrict Cloud Storage access based on request context, such as network origin or device state, blocking downloads by users outside the organisation. This satisfies the requirement to prevent external parties from downloading sensitive objects.
- ✗
Cloud DLP
Why it's wrong here
Cloud DLP discovers and de-identifies sensitive data within storage, but it neither authorises downloads nor blocks copying into external projects. It is tempting because DLP is the natural fit when the requirement is classifying and redacting regulated content such as personally identifiable information at rest.
- ✓
VPC Service Controls
Why this is correct
VPC Service Controls builds a service perimeter around Cloud Storage, blocking data exfiltration to resources outside the perimeter — including external projects and unauthorised networks. This directly satisfies the requirement to prevent copying data to external projects, complementing identity-based download restrictions.
- ✗
Cloud KMS
Why it's wrong here
Cloud KMS creates and manages encryption keys, so it protects data confidentiality at rest but does not govern who may download objects or copy them across projects. It is tempting because KMS is correct when the requirement is controlling key rotation, separation of duties or customer-managed encryption keys.
- ✗
Cloud Armor
Why it's wrong here
Cloud Armor filters HTTP(S) traffic at the edge against web attacks, and holds no authority over Cloud Storage object access or project boundaries. It is tempting because it is the right choice when the requirement is blocking SQL injection, cross-site scripting or volumetric denial-of-service traffic reaching an external load balancer.
Go deeper
Related to this question
Learn chapter
Data Lifecycle Management on Google Cloud
Key term
KMS
KMS (Key Management Service) is a Microsoft technology that automates volume licensing activation for Windows and Office products within an organization's network.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.