GCP Professional Cloud Security Engineer Practice Question

A healthcare analytics company plans to spin up Vertex AI Workbench user-managed notebook instances for model training. Security architects mandate that notebook VMs must never expose external IP addresses, all traffic must remain inside the existing VPC Service Controls perimeter, and corporate policy bans use of the default network. Which network configuration satisfies these constraints while requiring the least ongoing network administration?

  • Use user-managed notebooks with public IP addresses but apply an organization policy that blocks all outbound internet traffic from the project.

  • Deploy each notebook in the default network, delete the default internet gateway route, and rely on firewall egress rules to block external traffic.

  • Launch notebooks in a shared host project that already uses Cloud NAT for egress and enable Private Google Access on that subnet.

  • Create the notebooks in a new custom VPC subnet that has Private Service Connect enabled, disable external IP assignment for the instances, and add the project to the existing VPC Service Controls perimeter.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot