GCP Professional Cloud Architect Practice Question
Project A hosts a highly regulated payment API on GKE behind an internal HTTP(S) load balancer. Several consumer projects-some in other Google Cloud organizations-must invoke the API using private RFC 1918 addresses. The security team has ruled out VPC Network Peering because of overlapping CIDR ranges and requires that no other producer subnet resources be reachable. All traffic must remain on Google's private backbone and avoid the public internet. Which Google Cloud networking construct meets these requirements while allowing the consumers to initiate the connection from their own VPCs?
Expose the API with an internal TCP/UDP load balancer enabled for global access and share its virtual IP through Cloud DNS across projects.
Create Cloud VPN tunnels from each consumer project to Project A and route traffic to the API through the tunnel.
Set up VPC Network Peering between Project A and every consumer project and advertise custom routes to the internal load balancer.
Publish the API through a Private Service Connect service attachment in Project A and allow each consumer project to create PSC endpoints that point to it.
Private Service Connect (PSC) lets a producer project publish a service attachment that exposes only specific load-balanced endpoints. Consumer projects create PSC endpoints in their own subnets, so they originate connections using their own private addresses; overlapping CIDRs are not a problem, and no additional routes are exchanged. Traffic stays on Google's private network and no external IPs are used. Internal load balancers with global access or Cloud DNS sharing still require the caller to be in the same VPC (or a peered one), so they fail the peering constraint. VPN tunnels similarly expose wider network access and leave routing to the customer, violating the subnet-isolation requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Private Service Connect in Google Cloud?
Open an interactive chat with Bash
How does PSC handle overlapping CIDR ranges between VPCs?
Open an interactive chat with Bash
Why does PSC ensure traffic remains on Google's private backbone?
Open an interactive chat with Bash
What is Private Service Connect (PSC)?
Open an interactive chat with Bash
Why is VPC Network Peering not suitable in this scenario?
Open an interactive chat with Bash
How does Google Cloud ensure traffic stays on its private backbone using PSC?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Designing and planning a cloud solution architecture
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .