GCP Professional Cloud Security Engineer Practice Question

Your company connects its on-premises data center to a Shared VPC in Google Cloud by using Dedicated Interconnect. Security policy states that:

  • On-premises workloads must call BigQuery and Cloud Storage APIs without using public IP addresses.
  • Any Google service that is not supported by VPC Service Controls must be unreachable from on-prem.
  • The network team wants to allow-list a single internal IP address for all permitted Google API traffic. Which design meets these requirements while keeping management overhead low?
  • Create a Private Service Connect endpoint in the VPC by reserving an internal IP address and specifying the vpc-sc Google APIs bundle. Publish private DNS A records that map only the needed API hostnames to that IP and advertise the address to on-prem over Cloud Router.

  • Deploy Cloud NAT with manually allocated public NAT IPs, then allow on-prem workloads to reach BigQuery and Cloud Storage through the NAT gateway.

  • Configure a Serverless VPC Access connector and protect the APIs with Identity-Aware Proxy (IAP) so that only approved users can invoke them from on-prem.

  • Enable Private Google Access on every subnet, add a private DNS zone that maps restricted.googleapis.com to 199.36.153.4, and let on-prem traffic reach Google APIs through that public VIP.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot