GCP Professional Cloud Security Engineer Practice Question

Your company's on-premises data-center network connects to a Google Cloud VPC through two HA VPN tunnels that exchange custom dynamic routes with a Cloud Router. For compliance reasons, the on-premises application servers must invoke Google Cloud Storage over private IP addresses-traffic must never traverse the public internet or use public source IPs. You must implement this requirement without changing application code or proxy configuration and without adding new connectivity products. Which actions will achieve the goal while keeping traffic on the existing VPN connection?

  • Deploy Cloud NAT for the VPN-terminating subnet, advertise a default route (0.0.0.0/0) to on-prem via BGP, and leave DNS unchanged so Google API hostnames resolve to public IPs.

  • Export a custom route for 199.36.153.8/30 through the Cloud Router and configure the on-premises DNS servers to resolve Google API hostnames (for example, storage.googleapis.com) to 199.36.153.8. Ensure VPC firewall rules allow egress from the VPN-terminating subnet to 199.36.153.8/30.

  • Enable Private Service Connect for Google APIs, allocate a regional internal address, and modify all application calls to use https://googleapis.internal/ endpoints.

  • Introduce a third-party proxy appliance in the VPC, expose its external IP to the data-center network, and configure applications to proxy HTTPS requests to Google Cloud Storage through it.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot