🔥 40% Off Crucial Exams Memberships — Deal ends today!

12 minutes, 18 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization uses a Dedicated Cloud Interconnect to link its on-premises data center with a hub VPC in Google Cloud. Security policy requires that on-prem workloads reach Cloud Storage only over private IP addresses, and that no other Google-managed services be reachable from on-prem. The network team also wants to avoid deploying additional proxy or NAT appliances on-prem and to minimize ongoing operational overhead. Which design meets these requirements?

  • Configure Cloud NAT in the hub VPC and allow on-prem traffic to egress through the NAT gateway after whitelisting Cloud Storage public IP ranges.

  • Enable Private Google Access for on-premises hosts and advertise the Google-owned 199.36.153.8/30 prefix over BGP so on-prem systems can reach all Google APIs privately.

  • Provision a Private Service Connect endpoint in the hub VPC that targets storage.googleapis.com, assign it an internal IP address, create a private DNS record for storage.googleapis.com pointing to that IP, and add a static /32 route on the on-prem router to send the traffic over the Interconnect.

  • Place the hub project inside a VPC Service Controls perimeter, enable restricted.googleapis.com, and use Private Google Access for on-prem to limit reachable services.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot