🔥 40% Off Crucial Exams Memberships — Deal ends today!

13 minutes, 5 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization operates two VPC networks in us-west1 and europe-west1. All Compute Engine VMs have only internal IP addresses but must occasionally access public SaaS applications on the internet. Security policy states that every outbound HTTP and HTTPS request must be filtered against approved URL categories, decrypted and inspected with a corporate-issued root certificate, and exported to Cloud Logging. The solution must be highly available, fully managed, and require minimal ongoing maintenance. Which architecture best meets these requirements?

  • Deploy Secure Web Proxy in each region behind an internal load balancer, create a proxy policy with URL filtering and threat intelligence, enable TLS inspection using a subordinate CA from Certificate Authority Service, and route all egress traffic to the proxy.

  • Create an external global HTTPS load balancer with Google-managed SSL certificates, enable Cloud IDS and Cloud Armor, and update the VPC default route to point to the load balancer VIP for all outbound traffic.

  • Run Squid proxy instances in managed instance groups in both regions, configure URL filtering and TLS interception with the corporate CA, place them behind an internal TCP load balancer, and send logs to Cloud Logging.

  • Enable Cloud NAT in each region and attach a Cloud Armor security policy with custom rules so Cloud NAT can filter and decrypt outbound TLS traffic before it reaches the internet.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot