Courseiva

Google PCA Design for security and compliance Practice Question

A security engineer is configuring VPC Service Controls to protect a project containing BigQuery datasets with PII. They want to prevent data exfiltration while allowing authorized users to query the data from outside the perimeter. Which configuration meets these requirements?

⚠ Common exam trap

A common mistake in Google PCA exams is thinking VPC Service Controls have a simple 'allow external access' toggle or a dedicated 'exfiltration exception' flag, when in reality the only way to grant external access is through Access Context Manager access levels or ingress/egress rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a perimeter that includes the project, and use an access level from Access Context Manager to grant access to authorized users.

VPC Service Controls use Access Context Manager (ACM) access levels to define granular, identity-based access conditions. By including the project in a perimeter and applying an access level that specifies authorized users (e.g., based on IP ranges, device state, or identity), you can allow those users to query BigQuery from outside the perimeter while blocking all other external traffic, preventing data exfiltration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a perimeter that includes the project, and set the 'allowed external access' flag to true.

    Why it's wrong here

    No 'allowed external access' flag exists in VPC Service Controls; access from outside the perimeter is granted through ingress rules bound to access levels. A boolean flag is tempting as a quick toggle, and access levels are the genuine construct for permitting identified users while blocking exfiltration.

  • ✗

    Create a perimeter and enable the 'exfiltration exception' for BigQuery.

    Why it's wrong here

    VPC Service Controls has no 'exfiltration exception' flag; ingress rules with access levels govern authorised external access. Enabling such a setting would weaken the perimeter rather than permit specific identities. Exceptions are tempting because they sound like a targeted allow, and access levels are the actual mechanism for that purpose.

  • ✗

    Create a perimeter that includes only Compute Engine instances, and use a separate perimeter for BigQuery.

    Why it's wrong here

    Splitting Compute Engine and BigQuery into separate perimeters leaves the BigQuery project's data outside the protected boundary, so exfiltration controls do not apply to it. A single perimeter containing the BigQuery project is required. Separate perimeters are tempting for scoping services, and they suit isolating unrelated workloads, not protecting one dataset.

  • ✓

    Create a perimeter that includes the project, and use an access level from Access Context Manager to grant access to authorized users.

    Why this is correct

    A VPC Service Controls perimeter around the project blocks data exfiltration, while an Access Context Manager access level defines the trusted conditions under which authorised identities may reach BigQuery from outside the perimeter. Both are required to permit legitimate queries without opening the boundary.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.