GCP Professional Cloud Security Engineer Practice Question
Your organization uses a Dedicated Cloud Interconnect to link its on-premises data center with a hub VPC in Google Cloud. Security policy requires that on-prem workloads reach Cloud Storage only over private IP addresses, and that no other Google-managed services be reachable from on-prem. The network team also wants to avoid deploying additional proxy or NAT appliances on-prem and to minimize ongoing operational overhead. Which design meets these requirements?
Configure Cloud NAT in the hub VPC and allow on-prem traffic to egress through the NAT gateway after whitelisting Cloud Storage public IP ranges.
Enable Private Google Access for on-premises hosts and advertise the Google-owned 199.36.153.8/30 prefix over BGP so on-prem systems can reach all Google APIs privately.
Provision a Private Service Connect endpoint in the hub VPC that targets storage.googleapis.com, assign it an internal IP address, create a private DNS record for storage.googleapis.com pointing to that IP, and add a static /32 route on the on-prem router to send the traffic over the Interconnect.
Place the hub project inside a VPC Service Controls perimeter, enable restricted.googleapis.com, and use Private Google Access for on-prem to limit reachable services.
Provisioning a Private Service Connect (PSC) endpoint in the hub VPC that specifically targets the Cloud Storage API satisfies every requirement. The PSC endpoint receives an internal RFC 1918 address from a chosen subnet and is bound only to storage.googleapis.com. You create a private DNS record so that storage.googleapis.com resolves to this internal IP for on-prem clients, and you configure a static /32 route on the on-prem router to forward traffic destined for that IP through the Dedicated Interconnect. Because only this single IP is routed and the PSC endpoint exposes just the Cloud Storage API, other Google services remain unreachable.
Private Google Access for on-prem would allow connectivity to all Google APIs, violating the restriction. Cloud NAT uses public egress IPs, so traffic would not remain private. A VPC Service Controls perimeter with restricted.googleapis.com still leaves numerous Google APIs accessible and doesn't provide a private in-VPC IP. Therefore, the PSC solution is the only option that meets all constraints without extra on-prem proxies or NAT devices.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Private Service Connect (PSC)?
Open an interactive chat with Bash
How does BGP work in Dedicated Interconnect setups?
Open an interactive chat with Bash
What is the role of private DNS records with PSC endpoints?
Open an interactive chat with Bash
What is Private Service Connect (PSC) in Google Cloud?
Open an interactive chat with Bash
How does Private Service Connect ensure only specific Google services are accessible?
Open an interactive chat with Bash
What is the role of the static /32 route in the solution?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .