🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 26 minutes remaining!

GCP Professional Cloud Architect Practice Question

A Cloud Run (fully managed) service deployed in europe-west1 must connect to an internal-only PostgreSQL VM that listens on 10.20.4.5 inside the project's custom VPC subnet 10.20.4.0/24. Security policy forbids assigning external IP addresses to either workload or allowing any outbound traffic over the public internet. The service currently times-out when it opens a TCP connection to 10.20.4.5. What single configuration change will enable the service to reach the database while satisfying the policy and without modifying the container image?

  • Create a Serverless VPC Access connector in europe-west1 using a non-overlapping /28 CIDR, attach it to the Cloud Run service, and add a firewall rule that permits traffic from the connector's IP range to 10.20.4.5.

  • Enable Private Google Access on the subnet that hosts the PostgreSQL VM so Cloud Run can resolve and reach the VM's private address.

  • Configure VPC Network Peering between the Cloud Run service and the custom VPC and rely on the default egress range.

  • Enable Cloud NAT on the subnet and set the Cloud Run service's egress setting to All traffic so the service can reach the VM via the NAT gateway.

GCP Professional Cloud Architect
Managing and provisioning a solution infrastructure
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot