Your team has deployed several Compute Engine instances in a custom VPC subnet that has no public IP addresses assigned to the VMs. The servers need to download operating-system updates from external repositories on the internet, but must remain inaccessible from the internet. You want a managed, highly available solution that requires the least ongoing maintenance. What should you do?
Deploy a single Compute Engine VM with two NICs, enable IP forwarding, and configure it as a manual NAT gateway for the subnet.
Reserve and assign static external IP addresses to each VM and rely on egress-only firewall rules to block inbound traffic.
Configure a Cloud NAT gateway on an existing Cloud Router and enable it for the subnet.
Enable Private Google Access on the subnet so the VMs can reach external update servers without external IP addresses.
Cloud NAT is a Google-managed network address translation service designed specifically for outbound connectivity from private VM instances. When you create a Cloud NAT gateway and attach it to a Cloud Router, every instance in the selected subnet can reach the public internet for software updates or other egress traffic without having an external IP address. Because Cloud NAT never accepts unsolicited inbound connections, the VMs remain unreachable from the internet, meeting the security requirement. Adding individual external IPs would satisfy outbound connectivity but violates the requirement to stay private and increases operational overhead. Building your own NAT instance introduces single-point-of-failure and patching tasks, while Private Google Access only allows access to Google APIs, not general internet repositories. Therefore, configuring a Cloud NAT gateway is the best option.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Cloud NAT and why is it preferable for private VM instances?
Open an interactive chat with Bash
How does Cloud NAT differ from deploying a manual NAT gateway with IP forwarding?
Open an interactive chat with Bash
What is the purpose of enabling Private Google Access on a subnet?
Open an interactive chat with Bash
What is Cloud NAT and how does it enhance security for VMs in a private subnet?
Open an interactive chat with Bash
Why is Private Google Access not sufficient for downloading operating-system updates from external repositories?
Open an interactive chat with Bash
What are the disadvantages of deploying a manual NAT gateway using a Compute Engine VM?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Ensuring successful operation of a cloud solution
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .