🔥 40% Off Crucial Exams Memberships — Deal ends today!

44 minutes, 41 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your retail platform is migrating a three-tier application to Google Cloud. Customer browsers must reach the web tier over HTTPS via a single globally routable IP address. Application and database VMs must remain inaccessible from the internet but need to initiate outbound connections to a third-party payment API that only accepts traffic from a fixed IP range you provide. Which design satisfies these requirements while following Google-recommended use of public and private IPs?

  • Give every VM in all three tiers both internal and external IP addresses; block unwanted traffic to the application and database tiers using firewall rules; no load balancer or NAT required.

  • Deploy a regional internal HTTP(S) load balancer with a private front-end address, publish a DNS A record for it on the public internet; give the application and database VMs external IPs so they can reach the payment API without NAT.

  • Attach a global external IP to an external HTTP(S) load balancer front-end; place all web, application, and database instances in subnets with only private addresses; configure a Cloud NAT gateway with a statically reserved public IP for the subnets needing egress.

  • Provision an internal HTTP(S) load balancer and assign public IPs directly to the web tier VMs; leave application and database tiers on private addresses; create Cloud NAT with auto-assigned IPs for outbound calls.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot