Google Professional Cloud DevOps Engineer exam dumps

Google Professional Cloud DevOps Engineer practice question 5 of 268

Professional Cloud DevOps Engineer. Associate level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud DevOps Engineer Question 5

Select 2Google Cloud Platform

Your organization uses a Shared VPC architecture in Google Cloud to centralize networking management across multiple projects. A new team needs to deploy an application in their own service project but requires access to an existing subnet in the host project for their workloads. As a DevOps Engineer, what steps should you take to ensure proper network access while maintaining security and central management?

  1. A

    Grant the service project Shared VPC Admin IAM role to manage the shared subnet.

  2. B

    Assign the appropriate subnet to the service project as a Shared VPC resource.

  3. C

    Grant the Compute Network User IAM role to the service project’s service accounts for the shared subnet.

  4. D

    Create a new subnet in the host project and share it with the service project.

  5. E

    Set up a Cloud VPN between the service project and host project to enable subnet access.

Show answer and explanation

Correct answers: B, C

Explanation

In a Shared VPC architecture, service projects can access subnets from the host project if they are explicitly shared. To maintain security and avoid over-provisioning permissions, you should assign the subnet as a shared resource to the service project and grant the Compute Network User IAM role to the service accounts that need access. This approach ensures proper access while adhering to the principle of least privilege.

  • A. Incorrect.

    Granting the Shared VPC Admin IAM role is unnecessary and provides excessive permissions. It allows the service project to modify the Shared VPC setup, which violates the principle of least privilege.

  • B. Correct.

    Assigning the existing subnet as a shared resource to the service project is a necessary step to enable access while maintaining the Shared VPC architecture.

  • C. Correct.

    Granting the Compute Network User IAM role to the appropriate service accounts ensures that the service project can use the shared subnet without gaining excessive permissions.

  • D. Incorrect.

    Creating a new subnet is not required because the application can use the existing subnet by configuring proper access.

  • E. Incorrect.

    Setting up a Cloud VPN is unnecessary in a Shared VPC architecture, as it is designed to avoid the need for such complex networking configurations.

Timed practice exam

Take a Google Professional Cloud DevOps Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam