🔥 40% Off Crucial Exams Memberships — Deal ends today!

10 minutes, 44 seconds remaining!

GCP Professional Cloud Architect Practice Question

Your company operates a private, VPC-native GKE cluster whose nodes have no external IP addresses. Application pods must call both an internal-IP Cloud SQL instance and the Vertex AI API. Security architects insist that traffic remain on Google's private network, your VPC's subnet CIDRs must not be exposed to Google-managed service networks, and each consumer project must get its own endpoint so usage and IAM controls stay isolated. Which connectivity approach best satisfies all requirements?

  • Create Private Service Connect endpoints for Cloud SQL and Google APIs in each consumer project's VPC subnet, and direct pod traffic to those internal IPs.

  • Enable Private Service Access by reserving an IP range and peering the VPC to the Google-managed service network that hosts Cloud SQL and Vertex AI.

  • Send traffic through Cloud NAT so pods reach Cloud SQL and Vertex AI over their public service endpoints, restricted by firewall rules.

  • Provision a Dedicated Cloud Interconnect VLAN attachment, advertise the cluster subnet, and route requests privately to Cloud SQL and Vertex AI through that path.

GCP Professional Cloud Architect
Managing and provisioning a solution infrastructure
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot