GCP Associate Cloud Engineer Practice Question

A development team created a Compute Engine VM that has no external IP address. They need to allow on-call engineers to open an SSH session from their laptops using the command gcloud compute ssh --tunnel-through-iap vm-1 --zone=us-central1-a. The command currently times out. Which change will allow the engineers to connect while keeping the VM private?

  • Enable interactive serial console access for the VM in its metadata settings.

  • Create an ingress firewall rule that allows TCP port 22 from source range 35.235.240.0/20 to the VM's network tag.

  • Reserve a static external IP address and assign it to the VM.

  • Configure a Cloud NAT gateway for the subnet that contains the VM.

GCP Associate Cloud Engineer
Ensuring successful operation of a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot