Google PCA Designing for Security and Compliance Practice Question
A company with multiple projects must ensure that no data can be exfiltrated from a specific project's Cloud Storage buckets to unauthorized locations outside the organization. They also need to allow access only from a corporate VPN IP range. Which configuration meets these requirements?
⚠ Common exam trap
Test-takers frequently confuse network-level controls (firewall rules, Cloud Armor) with service-level data exfiltration prevention; candidates often pick firewall rules because they think of 'blocking traffic,' but VPC Service Controls is the only option that creates a data boundary for managed services like Cloud Storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a VPC Service Controls perimeter with an access level restricted to the corporate VPN IP range.
VPC Service Controls creates a security perimeter around Google Cloud services (including Cloud Storage) that prevents data exfiltration by blocking access from outside the perimeter, even if IAM permissions would otherwise allow it. Access levels within the perimeter can be restricted to specific IP ranges (such as the corporate VPN CIDR), so only requests originating from those IPs can reach the protected resources. This combination of perimeter + access level directly satisfies both requirements: preventing exfiltration to unauthorized locations and limiting access to the VPN range.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a VPC Service Controls perimeter with an access level restricted to the corporate VPN IP range.
Why this is correct
VPC Service Controls perimeters block data exfiltration from Cloud Storage by restricting access to resources inside the perimeter, and the access level limits entry to the corporate VPN IP range. This satisfies both the exfiltration prevention and VPN-only access constraints.
- ✗
Set firewall rules to block all traffic except from the VPN.
Why it's wrong here
Firewall rules govern network ingress and egress, not identity-based access to individual Cloud Storage buckets, so they cannot prevent exfiltration via authenticated API calls from within the VPN range. Firewalls are the right control when restricting traffic to specific ports, protocols or subnets at the network perimeter.
- ✗
Use IAM conditions to restrict access based on IP address.
Why it's wrong here
IAM conditions restricting by IP address control who may access buckets, but do not stop an authorised principal from copying data to an external destination; exfiltration prevention requires a VPC Service Controls perimeter. IAM conditions suit limiting access to corporate networks for user authentication scenarios.
- ✗
Use Cloud Armor with IP whitelisting.
Why it's wrong here
Cloud Armor filters traffic at the HTTP(S) load balancer edge; it cannot restrict Cloud Storage bucket access or prevent exfiltration to external destinations. It is tempting because IP whitelisting sounds like the stated VPN requirement, and it is genuinely correct for protecting load-balanced web applications, not storage IAM.
Visual reference
Go deeper
Related to this question
Learn chapter
Security Best Practices and Compliance
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.