GCP Professional Cloud Architect Practice Question
Your organization has two Google Cloud projects: net-core (hosting centrally managed VPC subnets and firewall rules) and app-prod (where developers run Compute Engine VMs). Traffic between the VMs and shared services must remain on private RFC 1918 addresses, and the networking team must keep exclusive control over routing, subnet, and firewall configuration. What is the best way to enable private connectivity between resources in the two projects while meeting these governance requirements?
Designate the net-core project as a Shared VPC host and attach app-prod as a service project so its VMs use subnets from the host.
Provision Cloud VPN tunnels over the internet between the two VPC networks.
Create bidirectional VPC Network Peering between the existing VPCs and let each project manage its own firewall rules.
Use Private Service Connect endpoints exported from net-core and consume them in app-prod to enable private connectivity.
Sharing the VPC from the net-core project satisfies all requirements. Declaring net-core as a Shared VPC host lets the networking team own and manage the subnets, routes, and firewall rules. Attaching app-prod as a service project allows its developers to create VM instances that receive internal IPs from the host project's subnets and communicate privately with other resources in that network. VPC Network Peering or Cloud VPN would allow private connectivity, but each project would still manage its own routes and firewalls, violating the governance constraint. Private Service Connect exposes individual services, not general east-west VM-to-VM connectivity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Shared VPC, and how does it work in Google Cloud?
Open an interactive chat with Bash
What are RFC 1918 addresses, and why are they important for private connectivity?
Open an interactive chat with Bash
How does VPC peering differ from Shared VPC in Google Cloud?
Open an interactive chat with Bash
What is a Shared VPC in Google Cloud?
Open an interactive chat with Bash
What is the difference between VPC Network Peering and Shared VPC?
Open an interactive chat with Bash
How does traffic stay private within the Shared VPC setup?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Managing and provisioning a solution infrastructure
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .