Google PCA Designing for Security and Compliance Practice Question
Which Google Cloud service allows organizations to define perimeters that protect resources and data from exfiltration to other VPCs or networks?
⚠ Common exam trap
PCA often tests the confusion between network-level controls (Private Service Connect, Cloud Armor) and API-level data-exfiltration controls (VPC Service Controls) — the key discriminator is whether the question mentions preventing data movement across boundaries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPC Service Controls
VPC Service Controls lets organizations define service perimeters that restrict access to Google Cloud services and prevent data exfiltration across project, VPC, or network boundaries. It enforces context-aware access at the API level, blocking operations that would move data outside the perimeter even if IAM would otherwise allow them. This is exactly the 'protect resources and data from exfiltration to other VPCs or networks' requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Private Service Connect
Why it's wrong here
Private Service Connect publishes and consumes services across VPCs via endpoints; it does not define a boundary restricting where resources may send data. It is tempting because it does govern cross-network connectivity, which is correct for private service access rather than perimeter-based exfiltration control.
- ✗
Identity-Aware Proxy (IAP)
Why it's wrong here
Identity-Aware Proxy controls access to applications behind a load balancer; it does not define network perimeters around resources. It is tempting because IAP enforces identity-based access, which is correct for protecting web apps and VMs from unauthenticated users rather than preventing data exfiltration across VPCs.
- ✗
Cloud Armor
Why it's wrong here
Cloud Armor filters HTTP(S) traffic at the edge against DDoS and application-layer attacks; it cannot define resource perimeters or block exfiltration between VPCs. It is tempting because it is a security control, but it would be correct for protecting an external load balancer, whereas VPC Service Controls draws the perimeter.
- ✓
VPC Service Controls
Why this is correct
VPC Service Controls define service perimeters that restrict access to Google Cloud resources, preventing data exfiltration across project, VPC or network boundaries. This directly satisfies the requirement to protect resources and data from unauthorised movement to other VPCs or networks.
Go deeper
Related to this question
Learn chapter
Resource Monitoring and Logging with Cloud Operations
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
VPC Service Controls
VPC Service Controls is a Google Cloud security feature that protects the data of managed services by defining perimeters that prevent data exfiltration and unauthorized access across public networks.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.