GCP Professional Cloud Security Engineer Practice Question
Your organization operates two on-premises data centers that each terminate a 10-Gbps Dedicated Interconnect in separate Google Cloud metros. Security policy requires all production traffic between on-prem workloads and a Shared VPC in Google Cloud to be encrypted in transit, achieve a 99.99% availability SLA, and avoid traversing the public internet. Which connectivity design satisfies these requirements?
Replace the Dedicated Interconnect with Partner Interconnect and rely on Google Cloud's default encryption at rest and in transit without adding VPN encryption.
Enable MACsec on both Dedicated Interconnect links and rely solely on it for encryption without creating any VPN tunnels.
Deploy an HA VPN gateway in each data center, attach each gateway to separate VLAN attachments on the Dedicated Interconnect, and establish BGP-based HA VPN tunnels through two Cloud Routers to carry all production routes.
Create two Classic Cloud VPN tunnels from each data center over the public internet and use static routing to reach the Shared VPC.
Deploying HA VPN gateways over the existing Dedicated Interconnect links fulfills every constraint: the IPsec tunnels provide end-to-end encryption, the traffic stays on the private interconnect circuits (never touching the public internet), and the dual-tunnel, dual-attachment architecture backed by HA VPN and redundant Cloud Routers delivers the 99.99 % availability SLA. MACsec alone encrypts only the physical link and does not guarantee the higher-level redundancy, Classic VPN relies on the public internet and offers only 99.9 % SLA, and replacing the dedicated links with Partner Interconnect does not inherently add encryption.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is HA VPN in Google Cloud?
Open an interactive chat with Bash
Why doesn't MACsec alone meet the requirements?
Open an interactive chat with Bash
What is the role of Cloud Router in HA VPN architecture?
Open an interactive chat with Bash
What is Dedicated Interconnect in Google Cloud?
Open an interactive chat with Bash
What is HA VPN and how does it ensure high availability?
Open an interactive chat with Bash
Why is MACsec encryption insufficient for meeting the given requirements?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .