A healthcare analytics company stores sensitive patient datasets in a Cloud Storage bucket in the us-central1 region. A new regulation requires that the data never leave the United States and that access be restricted to a defined set of projects. The security team wants a guardrail that prevents any future project from reading the bucket unless it is explicitly authorized, while keeping administration simple. What should the architect implement?
VPC Service Controls creates a security perimeter that blocks access to protected services such as Cloud Storage from outside the perimeter, regardless of IAM grants. Placing the bucket and the authorized projects inside the perimeter ensures that any future project outside it cannot read the data even if it receives an IAM role, which directly meets the guardrail requirement while keeping administration centralized.
Why this answer
The regulation requires both a location boundary and a hard restriction on which projects may read the data. VPC Service Controls builds a perimeter that denies access to protected services from outside the perimeter, so even a project that later receives an IAM role cannot read the bucket unless it is inside the perimeter. This gives a centralized guardrail that IAM or resource location constraints alone cannot provide.
Exam trap
The trap here is treating an IAM policy or a resource location constraint as a complete data-residency guardrail, when only a VPC Service Controls perimeter blocks access from projects outside an authorized boundary.