GCP Professional Cloud Security Engineer Practice Question
A security-sensitive workload runs on a Compute Engine VM in a Shared VPC service project. The VM is placed in a private subnet that has no external IP address, and the organization must meet these requirements:
The VM needs programmatic access to Cloud Storage and BigQuery APIs.
No other outbound internet traffic must be possible from the subnet.
The design must minimize operational overhead and avoid adding new gateways outside the VPC.
You are asked to provide the networking configuration that satisfies all requirements. What should you do?
Enable Private Google Access on the subnet and add an egress firewall rule that denies 0.0.0.0/0 except 199.36.153.8/30.
Assign a temporary external IP address to the VM, enable Cloud Armor WAF, and rely on IAM to protect the APIs.
Configure Private Service Connect endpoints for the required APIs and advertise a default-route-reject community on the Cloud Router.
Create a Cloud NAT gateway for the subnet and restrict egress with a custom static route to 199.36.153.8/30.
Enabling Private Google Access (PGA) on the subnet lets VMs that have only internal addresses reach Google APIs by sending traffic to the well-known 199.36.153.8/30 virtual IP range, which is routed inside Google's network and never egresses to the public internet. Because PGA does not affect other destinations, you must still add a VPC egress firewall rule that denies all traffic to 0.0.0.0/0 except for the PGA destination range. This blocks any non-Google internet access while permitting the required Cloud Storage and BigQuery calls. Creating Cloud NAT, giving the VM an external IP, or using Private Service Connect for Google APIs would either allow broader internet egress than permitted or add unnecessary operational components.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Private Google Access (PGA)?
Open an interactive chat with Bash
Why is an egress firewall rule with 199.36.153.8/30 necessary?
Open an interactive chat with Bash
Why is Cloud NAT not used in this setup?
Open an interactive chat with Bash
What is Private Google Access (PGA)?
Open an interactive chat with Bash
Why is 199.36.153.8/30 used in this configuration?
Open an interactive chat with Bash
Why is Cloud NAT not suitable in this case?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .