Valid Professional-Cloud-Security-Engineer Dumps shared by ExamDiscuss.com for Helping Passing Professional-Cloud-Security-Engineer Exam! ExamDiscuss.com now offer the newest Professional-Cloud-Security-Engineer exam dumps, the ExamDiscuss.com Professional-Cloud-Security-Engineer exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com Professional-Cloud-Security-Engineer dumps with Test Engine here:
Your Security team believes that a former employee of your company gained unauthorized access to Google Cloud resources some time in the past 2 months by using a service account key. You need to confirm the unauthorized access and determine the user activity. What should you do?
Correct Answer: D
* Objective: Ensure that a Cloud Storage bucket in Project A can only be readable from Project B and prevent data access or copying to Cloud Storage buckets outside the network, even with correct credentials. * Solution: Use VPC Service Controls to create a security perimeter. * Steps: * Step 1: Open the Google Cloud Console. * Step 2: Navigate to the VPC Service Controls page. * Step 3: Create a new service perimeter. * Step 4: Add Project A and Project B to the service perimeter. * Step 5: Include Cloud Storage service in the perimeter configuration. * Step 6: Define access levels to ensure that only resources within the perimeter can access the Cloud Storage bucket. By setting up a VPC Service Controls perimeter, you can enforce security boundaries that restrict data access and movement to within defined projects, providing an extra layer of protection beyond IAM permissions. References: * VPC Service Controls Overview * Configuring VPC Service Controls