PDE Storing the Data Practice Question
An organization needs to restrict access to BigQuery and Cloud Storage so that data can only be accessed from within a specific VPC network and cannot be exfiltrated. Which Google Cloud feature should they use?
⚠ Common exam trap
A common mix-up: candidates confuse VPC firewall rules (which control network traffic) with VPC Service Controls (which control data access at the API layer), leading them to choose firewall rules because they think 'restricting access to a VPC' is purely a network-level concern.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPC Service Controls
VPC Service Controls (option B) is the correct choice because it creates a security perimeter around Google Cloud services like BigQuery and Cloud Storage, preventing data exfiltration even from within a VPC. It enforces context-aware access based on the VPC network, ensuring data can only be accessed from authorized VPC sources and blocking unauthorized transfers outside the perimeter.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Private Service Access
Why it's wrong here
Private Service Access only allocates internal IP ranges for Google-managed services over private peering; it does not evaluate caller identity or network origin per request. It is tempting because it keeps BigQuery and Cloud Storage traffic off the public internet, which is its actual purpose, but exfiltration prevention requires VPC Service Controls perimeter rules.
- ✓
VPC Service Controls
Why this is correct
VPC Service Controls builds a service perimeter around BigQuery and Cloud Storage, permitting access only from within the specified VPC network and blocking data exfiltration to unauthorised projects. This directly satisfies the constraint that data remain accessible solely from inside the defined network boundary.
- ✗
VPC firewall rules
Why it's wrong here
VPC firewall rules filter traffic to and from Compute Engine instances by IP, port and protocol; they never inspect API calls to BigQuery or Cloud Storage, which terminate on Google's service infrastructure outside the VPC. They are the right tool for instance-level network segmentation, but here VPC Service Controls must define the perimeter.
- ✗
IAM conditions
Why it's wrong here
IAM conditions evaluate attributes such as resource name, request time or tags, not the caller's VPC network origin, so they cannot confine BigQuery and Cloud Storage access to a specific network. They are genuinely useful for time-bound or resource-scoped grants, which is why they attract attention, but VPC Service Controls enforces the network perimeter.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.