🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 52 minutes remaining!

GCP Associate Cloud Engineer Practice Question

Your security team requires that worker nodes in a new Google Kubernetes Engine (GKE) cluster never receive public IP addresses. The cluster's control-plane must be reachable only from the company's on-premises network (10.1.0.0/16) over an existing Cloud VPN tunnel. Workloads must still be able to pull container images from Artifact Registry and send logs to Cloud Logging. Which configuration will meet all of these requirements?

  • Create a private GKE cluster but leave the public control-plane endpoint enabled with a master-authorized-network entry for 10.1.0.0/16, and disable Private Google Access on the subnet.

  • Create a standard (public) GKE cluster, remove external IPs from the node pool template, and restrict SSH access with firewall rules. Use Cloud NAT so nodes can reach Artifact Registry and Cloud Logging.

  • Create a private GKE cluster, disable the private endpoint, and enable Cloud NAT for the subnet so nodes can reach Google APIs while the control-plane is accessed through its public endpoint.

  • Create a private GKE cluster, enable the private control-plane endpoint and disable the public endpoint, and enable Private Google Access on the cluster's subnet. Use the existing Cloud VPN to reach the private endpoint from 10.1.0.0/16.

GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot