🔥 40% Off Crucial Exams Memberships — Deal ends today!

23 minutes, 23 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company enforces VPC Service Controls to protect sensitive data in Cloud Storage and BigQuery. Linux virtual machines in the prod-vpc subnet have only internal IP addresses but need to call those two services. All other Google APIs must be blocked to reduce the data-exfiltration surface, and no application code changes are allowed. Which network configuration change will meet the security goal with the least operational overhead?

  • Add an egress VPC firewall rule that denies TCP 443 to 0.0.0.0/0 except for the private.googleapis.com VIP range (199.36.153.4/30).

  • Create a private Cloud DNS zone that resolves *.googleapis.com to the restricted.googleapis.com VIP (199.36.153.8/30) and keep Private Google Access enabled on the subnet.

  • Deploy a Cloud NAT gateway and configure destination filters so that only the public IP ranges of Cloud Storage and BigQuery can be reached.

  • Insert an external HTTP(S) load balancer with custom URL maps in front of the VMs and allow only paths that match storage.googleapis.com and bigquery.googleapis.com.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot