Examtopics

Professional Cloud Security Engineer
  • Topic 1 Question 280

    Your organization has an application hosted in Cloud Run. You must control access to the application by using Cloud Identity-Aware Proxy (IAP) with these requirements:

    • Only users from the AppDev group may have access. • Access must be restricted to internal network IP addresses.

    What should you do?

    • Deploy a VPN gateway and instruct the AppDev group to connect to the company network before accessing the application.

    • Create an access level that includes conditions for internal IP address ranges and AppDev groups. Apply this access level to the application's IAP policy.

    • Configure firewall rules to limit access to IAP based on the AppDev group and source IP addresses.

    • Configure IAP to enforce multi-factor authentication (MFA) for all users and use network intrusion detection systems (NIDS) to block unauthorized access attempts.


    シャッフルモード