GCP Professional Cloud Architect Practice Question

Your company runs an internal dashboard on GKE that is published through an external HTTP(S) load balancer with a public IP address. The security policy states:

  1. Only corporate employees may reach the dashboard from any network.
  2. Access must be denied from laptops that are not compliant with corporate device policies.
  3. No VPN clients or per-device certificates may be required.

As the Cloud Architect, which solution best satisfies these requirements while keeping operational overhead low?

  • Enable Identity-Aware Proxy on the HTTP(S) load balancer and create a context-aware access policy that permits only members of the corporate Workspace group on managed devices verified by Chrome Enterprise Premium.

  • Configure IAP TCP forwarding to a bastion host, force users to establish an SSH tunnel to the dashboard, and permit access only to the corporate group.

  • Protect the load balancer with Cloud Armor by allow-listing corporate office IP ranges and enforce basic authentication on the application.

  • Require users to connect through Cloud VPN to a private VPC that exposes the dashboard via an internal load balancer, and restrict firewall rules to the VPN subnet.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot