Free Google Cloud Certified - Professional Cloud Security Engineer practice — 6 questions on Securing Communications and Boundary Protection, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Securing Communications and Boundary Protection
A VPC Service Controls perimeter protects a BigQuery dataset in Project A. A Dataflow job running in Project B, which is outside the perimeter, needs to read from this dataset using one specific service account. The security team wants to allow only this exact service account to read only this specific dataset, without exposing any other resources or identities. Which configuration meets this requirement?
Ingress rules govern requests originating from outside a perimeter that target protected resources inside it. Since the service account and Dataflow job live outside the perimeter and the BigQuery dataset is inside, an ingress rule scoped to that identity and that exact dataset grants the narrowest possible access.
Question 2 of 6 · Securing Communications and Boundary Protection
A company runs a SaaS analytics platform in its own VPC and needs to expose one specific internal service to hundreds of customer VPCs that belong to different organizations. The company cannot require customers to coordinate non-overlapping IP ranges, and does not want to expose its full VPC CIDR range to any consumer. Which connectivity option should it use?
Private Service Connect publishes a specific service via a service attachment; consumers connect through a PSC endpoint in their own VPC. There is no CIDR overlap constraint, the producer's full network is never exposed, and it scales to many independent consumer VPCs across organizations.
Question 3 of 6 · Securing Communications and Boundary Protection
An organization's Cloud NAT gateway uses manual port allocation with a static minimum of 64 ports per VM instance. During a load test, some VM instances exhaust their allocated ports and fail to open new outbound connections, while other instances on the same gateway have unused port capacity. What should the team do to resolve this while keeping per-instance allocation predictable?
Dynamic Port Allocation lets each VM's port count scale between a configured minimum and maximum based on actual demand, so busy instances can burst above the static 64-port floor while idle instances release unused ports back to the pool — directly solving uneven exhaustion.
Question 4 of 6 · Securing Communications and Boundary Protection
A company requires a 99.99% availability SLA for an HA VPN connection between its on-premises data center and a VPC network. Which topology is required to achieve this SLA level?
The 99.99% SLA topology requires redundancy on both sides: both interfaces of the HA VPN gateway must each connect to a peer device/interface, resulting in four tunnels total. This ensures no single point of failure on either the Google Cloud side or the on-premises side.
Question 5 of 6 · Securing Communications and Boundary Protection
A security team must allow outbound internet access from VM instances in a private subnet to only specific SaaS domains (for example, *.salesforce.com) over HTTPS, block all other outbound web destinations, and retain visibility into which service account made each web request. Which Google Cloud service should they deploy?
Secure Web Proxy performs Layer 7 URL/domain-based filtering for egress web traffic, supports TLS interception, and integrates with IAM to apply and log policy per calling identity such as a service account — matching both the domain-restriction and per-identity visibility requirements.
Question 6 of 6 · Securing Communications and Boundary Protection
Which statement correctly describes Cloud DNS Response Policy Zones (RPZs) in the context of network boundary security design?
Response Policy Zones let administrators override the standard DNS response for specified domains — for example, returning NXDOMAIN for known-malicious domains or redirecting queries for internal names — providing a policy enforcement point at the DNS layer for boundary defense.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.