🔥 40% Off Crucial Exams Memberships — Deal ends today!

44 minutes, 52 seconds remaining!

GCP Associate Cloud Engineer Practice Question

Your production Compute Engine VM instances run without external IP addresses for security reasons. A team of site reliability engineers must occasionally SSH into these VMs from their laptops. You decide to enable Identity-Aware Proxy (IAP) TCP tunneling. Which additional change is required so the engineers can establish the SSH session through IAP?

  • Create an ingress firewall rule that permits TCP port 22 from the 35.235.240.0/20 source range to the target instances.

  • Add the VMs to a TCP load balancer backend service listening on port 22 and point IAP to the load balancer's IP.

  • Enable Cloud NAT on the subnet so the VMs can reach the internet during the SSH session.

  • Reserve a regional external static IP address and attach it to each VM before enabling IAP.

GCP Associate Cloud Engineer
Ensuring successful operation of a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot