🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 59 minutes remaining!

GCP Associate Cloud Engineer Practice Question

Your VPC contains two managed instance groups in the same region. Instances in the bastion group are created with the service account bastion-sa, and instances in the application group are created with the service account app-sa. You must allow administrators to open SSH sessions (TCP port 22) from the bastion hosts to the application hosts while blocking SSH traffic that originates from any other source. You want to meet the requirement without relying on fixed IP ranges or network tags. What should you do?

  • Create a single ingress firewall rule that applies to instances with the app-sa service account, sets the source service account to bastion-sa, and allows tcp:22.

  • Add a network tag "bastion" to the bastion instances and an "app" tag to the application instances. Create an ingress rule that allows tcp:22 from source tag "bastion" to target tag "app".

  • Create an egress firewall rule that applies to instances with the bastion-sa service account, sets the destination service account to app-sa, and allows tcp:22.

  • Enable OS Login and grant the bastion-sa service account the Compute OS Admin Login IAM role on the project; no firewall rule changes are required.

GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot