Courseiva

Google PCA Designing for Security and Compliance Practice Question

A company with multiple projects must ensure that no data can be exfiltrated from a specific project's Cloud Storage buckets to unauthorized locations outside the organization. They also need to allow access only from a corporate VPN IP range. Which configuration meets these requirements?

⚠ Common exam trap

Test-takers frequently confuse network-level controls (firewall rules, Cloud Armor) with service-level data exfiltration prevention; candidates often pick firewall rules because they think of 'blocking traffic,' but VPC Service Controls is the only option that creates a data boundary for managed services like Cloud Storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a VPC Service Controls perimeter with an access level restricted to the corporate VPN IP range.

VPC Service Controls creates a security perimeter around Google Cloud services (including Cloud Storage) that prevents data exfiltration by blocking access from outside the perimeter, even if IAM permissions would otherwise allow it. Access levels within the perimeter can be restricted to specific IP ranges (such as the corporate VPN CIDR), so only requests originating from those IPs can reach the protected resources. This combination of perimeter + access level directly satisfies both requirements: preventing exfiltration to unauthorized locations and limiting access to the VPN range.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure a VPC Service Controls perimeter with an access level restricted to the corporate VPN IP range.

    Why this is correct

    VPC Service Controls perimeters block data exfiltration from Cloud Storage by restricting access to resources inside the perimeter, and the access level limits entry to the corporate VPN IP range. This satisfies both the exfiltration prevention and VPN-only access constraints.

  • ✗

    Set firewall rules to block all traffic except from the VPN.

    Why it's wrong here

    Firewall rules govern network ingress and egress, not identity-based access to individual Cloud Storage buckets, so they cannot prevent exfiltration via authenticated API calls from within the VPN range. Firewalls are the right control when restricting traffic to specific ports, protocols or subnets at the network perimeter.

  • ✗

    Use IAM conditions to restrict access based on IP address.

    Why it's wrong here

    IAM conditions restricting by IP address control who may access buckets, but do not stop an authorised principal from copying data to an external destination; exfiltration prevention requires a VPC Service Controls perimeter. IAM conditions suit limiting access to corporate networks for user authentication scenarios.

  • ✗

    Use Cloud Armor with IP whitelisting.

    Why it's wrong here

    Cloud Armor filters traffic at the HTTP(S) load balancer edge; it cannot restrict Cloud Storage bucket access or prevent exfiltration to external destinations. It is tempting because IP whitelisting sounds like the stated VPN requirement, and it is genuinely correct for protecting load-balanced web applications, not storage IAM.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.