Courseiva

Google PCA Design for security and compliance Practice Question

A company stores sensitive customer data in Cloud Storage buckets. They want to ensure that access to these buckets is only allowed from within their VPC network. Which configuration should they use?

⚠ Common exam trap

Many candidates confuse VPC Service Controls with Private Google Access or IAM conditions, not realizing that VPC-SC is the only option that enforces network-level boundaries for Google-managed services like Cloud Storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Service Controls with a service perimeter

D is correct because VPC Service Controls (VPC-SC) allow you to define a service perimeter that restricts access to Google Cloud Storage (and other managed services) to only requests originating from a specified VPC network. This ensures that data exfiltration and unauthorized access from outside the VPC are blocked, even if the bucket is publicly accessible or IAM allows broader access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Bucket IAM policies with condition on service account

    Why it's wrong here

    IAM conditions on a service account still authorise that identity from any network, so access is not confined to the VPC. It is tempting because IAM conditions can restrict by request attributes, but the requirement is a network-origin boundary, which VPC Service Controls perimeter or an access-level condition enforces.

  • ✗

    Cloud Armor WAF rules

    Why it's wrong here

    Cloud Armor protects HTTP(S) load-balanced backends at layer 7; it cannot govern Cloud Storage bucket access, which uses the storage API rather than an external HTTP(S) load balancer. It is tempting because Cloud Armor filters traffic by origin, but its correct use is shielding web applications, not restricting bucket access to a VPC.

  • ✗

    Private Google Access for on-premises

    Why it's wrong here

    Private Google Access for on-premises lets on-premises hosts reach Google APIs and services using internal IP addresses; it does not restrict bucket access to a VPC. It is tempting because it concerns private connectivity to Cloud Storage, but it addresses routing from on-premises, not the VPC-SC perimeter or IAM condition that enforces VPC-only access.

  • ✓

    VPC Service Controls with a service perimeter

    Why this is correct

    VPC Service Controls perimeters restrict Cloud Storage access to authorised VPC networks, blocking requests originating outside the perimeter even with valid credentials. This directly enforces the requirement that bucket access occur only from within the company's VPC network, mitigating data exfiltration.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.