🔥 40% Off Crucial Exams Memberships — Deal ends today!

44 minutes, 54 seconds remaining!

GCP Associate Cloud Engineer Practice Question

A production VM runs in a private subnet and has no external IP address. Engineers must occasionally SSH into the VM from their laptops on the public internet. You must design the access method so that:

  • No public IP is added to the VM.
  • Inbound firewall rules remain restricted to internal traffic.
  • Only specific engineers can initiate SSH sessions. Which approach meets these requirements with the least additional configuration?
  • Grant each engineer the roles/iap.tunnelResourceAccessor role on the project and have them run: gcloud compute ssh my-vm --zone us-central1-a --tunnel-through-iap

  • Enable interactive serial console on the VM and have engineers connect with: gcloud compute connect-to-serial-port my-vm --zone us-central1-a

  • Create a Cloud NAT gateway for the subnet and instruct engineers to run: gcloud compute ssh my-vm --zone us-central1-a --nat

  • Assign the VM a temporary external IP address, open TCP 22 in a firewall rule from the engineers' office IP range, and have them run: gcloud compute ssh my-vm --zone us-central1-a

GCP Associate Cloud Engineer
Ensuring successful operation of a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot