GCP Professional Cloud Security Engineer Practice Question

Your organization operates two on-premises data centers that each terminate a 10-Gbps Dedicated Interconnect in separate Google Cloud metros. Security policy requires all production traffic between on-prem workloads and a Shared VPC in Google Cloud to be encrypted in transit, achieve a 99.99% availability SLA, and avoid traversing the public internet. Which connectivity design satisfies these requirements?

  • Replace the Dedicated Interconnect with Partner Interconnect and rely on Google Cloud's default encryption at rest and in transit without adding VPN encryption.

  • Enable MACsec on both Dedicated Interconnect links and rely solely on it for encryption without creating any VPN tunnels.

  • Deploy an HA VPN gateway in each data center, attach each gateway to separate VLAN attachments on the Dedicated Interconnect, and establish BGP-based HA VPN tunnels through two Cloud Routers to carry all production routes.

  • Create two Classic Cloud VPN tunnels from each data center over the public internet and use static routing to reach the Shared VPC.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot