🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 52 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization uses a Shared VPC whose host project contains a regional Cloud Router named cr-hub-us in us-central1. Two subnets exist in the same region: web-subnet (10.10.1.0/24) that must be able to reach the public internet, and db-subnet (10.10.2.0/24) that must never initiate internet egress. Network engineers also want to be sure that any new subnet added to the region will not automatically gain internet access. Which Cloud NAT configuration satisfies these requirements with the least operational overhead?

  • Create a Cloud NAT gateway on cr-hub-us in Specify subnet IP ranges mode and select only the primary range of web-subnet. Do not include db-subnet or any other subnet.

  • Create two Cloud NAT gateways: one on cr-hub-us for web-subnet and a second on a new Cloud Router dedicated to db-subnet, then add a custom black-hole route for 0.0.0.0/0 in db-subnet.

  • Create a Cloud NAT gateway on cr-hub-us in Auto mode (apply to all current and future subnets), then add a VPC egress firewall rule that denies 0.0.0.0/0 from db-subnet.

  • Enable Private Google Access on both subnets and omit Cloud NAT; workloads in web-subnet will automatically use Private Google Access for all outbound internet traffic.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot