🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 55 minutes remaining!

GCP Professional Cloud Architect Practice Question

Your company runs an internal administrative dashboard on Compute Engine VMs in a VPC. Today the VMs are behind an internal HTTP(S) load balancer and are reachable only over the corporate VPN. Management wants to retire the VPN and let employees reach the dashboard over the public Internet, but traffic must still be permitted only for authenticated users in the corp.example.com Google Workspace domain. You must minimize application changes and avoid distributing client certificates or static IP allow-lists. Which architecture should you implement?

  • Keep the internal load balancer and configure a new Cloud VPN gateway that employees dial-up on demand; use VPC firewall rules and Google Groups to restrict access.

  • Migrate the VMs behind an external HTTP(S) load balancer, enable Cloud IAP, grant the corporate Google Group the roles/iap.httpsResourceAccessor role, and add a VPC firewall rule allowing ingress only from Google Front End IP ranges.

  • Expose the dashboard through an external HTTP(S) load balancer with Cloud Armor enforcing a policy that accepts requests only when a signed JWT from Identity Platform is present in the headers.

  • Require each employee to establish an IAP-TCP tunnel to the individual VM instances and access the dashboard via forwarded localhost ports.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot