GCP Professional Cloud Architect Practice Question

Your security team wants to centralize network administration while allowing dozens of application teams to continue deploying Compute Engine VMs and GKE clusters in their own projects. They have provided these requirements:

  1. All workloads must use a common set of RFC 1918 subnets that are defined only once.
  2. Security engineers, and no one else, must manage firewall rules and routing.
  3. Application teams must not be able to create new subnetworks or modify firewall rules.
  4. Network egress charges should be consolidated on a single, centrally managed project to simplify cost governance. Which design best satisfies these requirements with the least operational overhead?
  • Build a central VPC with Cloud Routers that export custom routes to each application project over Dedicated Interconnect VLANs, allowing teams to retain full network-admin rights.

  • Maintain separate VPCs for each application project, deploy individual Cloud NAT gateways, and use VPC Service Controls to restrict traffic.

  • Peer every application project VPC with a central security VPC and rely on organization-level hierarchical firewall policies for rule enforcement.

  • Create a Shared VPC host project that owns the common VPC. Attach each application project as a service project and grant developers only the compute.networkUser (and, if needed, compute.subnetworkUser) roles; security engineers manage all firewall rules and routes in the host project.

GCP Professional Cloud Architect
Designing and planning a cloud solution architecture
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot