GCP Professional Cloud Security Engineer Practice Question

Your security team runs Linux VMs in two private subnets of the prod-vpc network in the us-central1 region. None of the instances have external IP addresses, yet they must regularly download security updates from public package repositories on the internet. An external software vendor also requires a single, stable source IP address (or very small, predictable set) to allowlist outbound traffic from this environment. The design must remain highly available across all zones in the region and demand minimal ongoing management. How should you configure egress so that you meet all requirements?

  • Establish VPC Network Peering to a Google-managed project and assign external IP addresses to the Cloud Router to provide outbound connectivity.

  • Enable Private Google Access on the subnets and deploy an internal HTTP(S) load balancer with serverless NEGs to proxy outbound traffic to the internet.

  • Reserve a regional static external address, create a single regional Cloud NAT gateway attached to a Cloud Router in us-central1, select both private subnets, and configure the gateway to use the reserved address with manual NAT IP allocation.

  • Create separate Cloud NAT gateways for each subnet using automatic NAT IP allocation so each VM uses the first available ephemeral external IP address.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot