🔥 40% Off Crucial Exams Memberships — Deal ends today!

3 hours, 1 minute remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization hosts an ERP stack on Compute Engine VMs inside the prod-vpc network. A new compliance mandate states that the Cloud SQL for PostgreSQL instance that backs the application must NEVER be reachable over the public internet, but it must stay accessible to

  1. application VMs in prod-vpc, and
  2. database administrators who connect from the corporate data-center through an existing Cloud VPN tunnel. What is the most operationally efficient configuration to meet this requirement?
  • Maintain the public IP and require all access to go through a hardened bastion VM that forwards traffic to the database.

  • Create the instance with Private IP enabled and delete or disable its public IP so that it is reachable only through the VPC network and connected VPN.

  • Expose the Cloud SQL endpoint behind an Internal TCP/UDP Load Balancer whose backend is the database instance.

  • Keep the public IP, but restrict it to the office's external CIDR by adding that range to the Cloud SQL authorized networks list.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot