GCP Professional Cloud Security Engineer Practice Question
Your company is deploying a three-tier application in a single VPC. Web-tier instances run in subnet-web, application-tier instances in subnet-app, and MySQL database VMs in subnet-db. Security requires that:
The database tier must accept traffic only from the application tier on TCP port 3306.
Traffic between the application and database tiers must be encrypted in transit, without administrators managing certificates on every VM. Which approach meets both requirements while minimizing operational overhead?
Create an ingress firewall rule that targets the database instances and allows TCP 3306 only from the application tier's service account, then deploy Anthos Service Mesh to both tiers and enforce strict mutual TLS so sidecar proxies transparently encrypt all traffic.
Place the database behind an internal TCP proxy load balancer with an uploaded SSL certificate and permit connections from the application subnet through the load balancer's forwarding rule.
Configure a Cloud VPN tunnel between subnet-app and subnet-db and allow TCP 3306 over the VPN to secure traffic without additional encryption measures.
Move the application and database instances into the same subnet, rely on Google Cloud's default in-transit encryption, and allow all internal traffic within the subnet.
Creating a firewall rule that targets the database VMs and allows ingress only on TCP 3306 from the application tier's service account enforces strict network isolation. Deploying Anthos Service Mesh with mesh-wide strict mutual TLS injects sidecar proxies that automatically obtain and rotate certificates, ensuring all traffic between the application and database tiers is transparently encrypted without manual certificate management.
By contrast, simply placing both tiers in the same subnet and relying on Google Cloud's default in-transit encryption removes tier isolation and still lacks application-layer mutual TLS. Positioning the database behind an internal TCP proxy load balancer secures traffic only up to the load balancer; traffic between the load balancer and the database remains unencrypted unless additional steps are taken. Establishing a Cloud VPN tunnel between two subnets in the same VPC is unsupported and would add unnecessary complexity and key-management overhead. Therefore, combining service-account-based firewall rules with Anthos Service Mesh strict mTLS best satisfies both requirements with minimal operational effort.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Anthos Service Mesh, and how does it enforce strict mutual TLS?
Open an interactive chat with Bash
Why use service accounts for firewall rules in Google Cloud?
Open an interactive chat with Bash
What is mutual TLS, and why is it used for securing traffic?
Open an interactive chat with Bash
What is Anthos Service Mesh and how does it ensure encrypted traffic?
Open an interactive chat with Bash
How do Google Cloud firewall rules enforce network isolation?
Open an interactive chat with Bash
What are the benefits of deploying strict mutual TLS (mTLS) over default in-transit encryption?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .