GCP Associate Cloud Engineer Practice Question

Your company's security team wants to guarantee that, by default, no new Compute Engine VM instances in any project can obtain an external IPv4 address. However, they also want the flexibility to grant an exception later for a specific project used by the penetration-testing team. Which Google Cloud feature best satisfies these requirements and what action should you take first?

  • Grant only the Compute Engine internal access IAM role to project owners and rely on VPC Service Controls to block public endpoints.

  • Create an Organization Policy at the Organization node that sets the constraint constraints/compute.vmExternalIpAccess to Deny.

  • Apply a VPC firewall rule at the Organization level that blocks all egress traffic from external IP addresses.

  • Attach a Cloud Armor security policy to every project's default network that denies traffic from 0.0.0.0/0.

GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot