Your company runs a regional managed instance group with virtual machines in zones us-central1-a and us-central1-b. For security, the VMs are created without external IP addresses, yet they must regularly retrieve operating-system updates from public repositories on the internet. Management wants a solution that provides high availability across zones while keeping operational effort to a minimum. Which approach should you take?
Reserve a regional external IPv4 address for every VM and attach it as a secondary interface so the instances can reach the internet directly.
Deploy two Cloud NAT gateways, one in each zone, use manual NAT IP allocation, and add custom routes so each VM uses the gateway in its own zone.
Launch a pair of third-party VM-based NAT appliances behind an internal load balancer and configure the VMs to forward all outbound traffic through the appliances.
Create a single regional Cloud NAT gateway on a Cloud Router in us-central1 and let it automatically allocate external IP addresses.
A regional Cloud NAT gateway is a Google-managed, distributed service. When you attach it to a Cloud Router in the same region, it automatically scales and provides outbound connectivity for all subnets and zones in that region without per-zone configuration. Granting each VM an external IP would violate the security requirement. Creating separate NAT gateways per zone or deploying third-party appliances would add unnecessary management overhead and complexity without improving availability beyond what the regional Cloud NAT service already guarantees.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Cloud NAT and how does it work?
Open an interactive chat with Bash
Why is a regional Cloud NAT gateway better for high availability compared to separate zone-level NAT configurations?
Open an interactive chat with Bash
How does a Cloud NAT improve security compared to directly assigning external IPs to VMs?
Open an interactive chat with Bash
What is Cloud NAT in GCP and how does it work?
Open an interactive chat with Bash
Why is a regional Cloud NAT gateway preferable to multiple zonal NAT setups?
Open an interactive chat with Bash
What is the role of a Cloud Router in GCP with Cloud NAT?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Ensuring successful operation of a cloud solution
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .