GCP Professional Cloud Security Engineer Practice Question

Your company is building a multi-tier e-commerce platform on Google Cloud. The web tier must be reachable from any customer on the public internet, while the application and database tiers must remain isolated from unsolicited inbound traffic and must not expose any routable address space externally. Which configuration meets these requirements with the least operational overhead?

  • Place the web servers behind an external HTTP(S) load balancer that owns a Google-managed public IP, give the web, app, and database VMs only private RFC 1918 addresses, and use firewall rules to allow traffic from the load balancer to the private tiers.

  • Assign individual public external IP addresses to the web and application tiers, create firewall rules to block all ports except 443, and deploy Cloud NAT for the database tier.

  • Give the web and application tiers private IP addresses only, configure Private Google Access, and publish the database tier through Cloud NAT with a reserved static public IP.

  • Deploy all tiers in a public subnet with auto-assigned external IP addresses and rely on default VPC firewall rules to prevent unwanted inbound access.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot