🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 30 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company operates a production VPC with two private subnets in europe-west1. A Cloud Router peers with an HA VPN gateway that connects to the on-premises network, and a Cloud NAT gateway attached to that router was provisioned by using automatic subnet discovery. During testing, developers in subnet app-svc (10.50.2.0/24) can reach the public internet as expected, but database nodes in subnet db-svc (10.50.3.0/24) are also being NATed, violating a policy that forbids internet access from db-svc. Which configuration change best enforces the policy while continuing to use the same NAT IP addresses for app-svc only?

  • Disable Private Google Access on the db-svc subnet so its instances cannot reach external addresses.

  • Create a high-priority egress firewall rule on the db-svc subnet that denies traffic to 0.0.0.0/0.

  • Deploy a second Cloud NAT gateway dedicated to db-svc and configure it with no external IP addresses.

  • Reconfigure the existing Cloud NAT gateway to use manual (custom) subnetworks mode and include only the app-svc subnet's primary range.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot