Bird
0
0

After setting up a VPC Service Controls perimeter, external users can still access Cloud Storage buckets inside it. What is the most probable reason?

medium📝 Debug Q6 of 15
GCP - Cloud IAM Advanced
After setting up a VPC Service Controls perimeter, external users can still access Cloud Storage buckets inside it. What is the most probable reason?
AThe perimeter is configured as a dry run and not enforced
BThe perimeter does not include the Cloud Storage service in restrictedServices
CThe users have IAM roles granting access outside the perimeter
DThe perimeter includes only BigQuery but not Cloud Storage
Step-by-Step Solution
Solution:
  1. Step 1: Understand perimeter enforcement

    VPC Service Controls restrict access only to services listed in restrictedServices.
  2. Step 2: Check restrictedServices list

    If Cloud Storage is not included, perimeter won't block access to it.
  3. Step 3: Consider other options

    Dry run mode would not enforce restrictions but is less common; IAM roles do not override perimeter restrictions.
  4. Final Answer:

    The perimeter does not include the Cloud Storage service in restrictedServices -> Option B
  5. Quick Check:

    Verify restrictedServices includes all intended services. [OK]
Quick Trick: Ensure all services are listed in restrictedServices. [OK]
Common Mistakes:
  • Assuming IAM roles bypass perimeter restrictions
  • Not including all services in restrictedServices
  • Confusing dry run mode with enforcement

Want More Practice?

15+ quiz questions · All difficulty levels · Free

Free Signup - Practice All Questions
More GCP Quizzes