Your company connects on-premises to Google Cloud through Cloud VPN. You need to deploy a Google Kubernetes Engine (GKE) cluster for a customer-facing microservices platform. Nodes must use only internal IP addresses to reduce the attack surface. The Kubernetes control plane must be replicated across multiple zones in the region. Operations wants Google to manage node provisioning, patching, and automatic scaling. Which GKE deployment option satisfies all requirements?
Create a public Autopilot regional cluster and restrict access with firewall rules.
Create a private standard regional cluster and enable node auto-upgrade.
A private Autopilot regional cluster meets every stated requirement. Autopilot mode lets Google fully manage the data-plane nodes-including provisioning, patching, and automatic scaling-so the operations team does not manage VM instances. Marking the cluster as private ensures that nodes receive only internal RFC 1918 addresses and have no external IPs, reducing exposure. Choosing a regional control plane replicates masters in at least three zones within the region, providing high availability.
A standard private regional cluster would meet the networking and control-plane requirements but still leaves node lifecycle management to the operations team. An Autopilot zonal private cluster removes node administration work but uses a single-zone control plane, which does not satisfy the high-availability requirement. A public Autopilot cluster assigns a public endpoint to the control plane, which is outside the stated security goals.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a private Autopilot regional cluster in GKE?
Open an interactive chat with Bash
Why is internal IP addressing important in private GKE clusters?
Open an interactive chat with Bash
What is the benefit of deploying a regional control plane in GKE?
Open an interactive chat with Bash
What is the difference between an Autopilot and Standard GKE cluster?
Open an interactive chat with Bash
What makes a GKE cluster 'private'?
Open an interactive chat with Bash
Why is a regional control plane important in GKE?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .