GCP Associate Cloud Engineer Practice Question

Your team wants to let contractors open an SSH session to a Linux VM directly from the Google Cloud console by clicking the "SSH" button in the VM instances list. The VM has an external IP and no existing ingress rules. The contractors must not install the gcloud CLI or manage SSH keys locally. Which single configuration change is required so the browser-based SSH connection succeeds while keeping access as restrictive as possible?

  • Attach a Cloud NAT gateway to the subnet so the VM can establish outbound connections for the SSH session.

  • Add an ingress firewall rule that allows TCP 22 from source range 0.0.0.0/0 to the VM's network tags.

  • Create an ingress firewall rule that allows TCP 22 from source range 35.235.240.0/20 in the VPC network where the VM resides.

  • Enable OS Login at the project level so Compute Engine injects temporary SSH keys for the contractors.

GCP Associate Cloud Engineer
Ensuring successful operation of a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot