🔥 3-day streak
Google Cloud Professional Cloud Network Engineer140 / 142
Question 140 of 142

A financial services company stores sensitive customer data in BigQuery and Cloud Storage within a Google Cloud project. The security team is concerned that a compromised service account or a malicious insider could copy data to a personal project outside the organization. They want to ensure that even users with valid IAM permissions cannot exfiltrate data to resources outside a defined boundary, while still allowing authorized on-premises analysts to query the data over a private connection. Which approach best meets these requirements?

Reviewed for accuracy · Report an issueNext question