GCP Professional Cloud Security Engineer Practice Question

Your company has two Google Cloud projects: prod-app hosts several GKE clusters, and prod-data hosts internal REST services on Compute Engine VMs. The clusters must call the services over private IPs with high throughput and low latency. Security wants each team to keep project-level IAM separation, but networking must centrally manage subnets, routes, and firewall policies and avoid the non-transitive routing limitation if new projects are added later. Which connectivity design best meets these requirements?

  • Create a VPC Network Peering connection between the prod-app and prod-data VPCs and add custom routes for the service CIDRs.

  • Expose the prod-data services through a Private Service Connect service attachment and have prod-app create PSC endpoints to consume them, keeping the VPCs separate.

  • Create an HA VPN connection between the two projects with dynamic routing to exchange private routes.

  • Migrate both projects to a Shared VPC by designating a new host project and attaching prod-app and prod-data as service projects that deploy resources into centrally managed subnets.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot