Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 17 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 17

Select 2Google Cloud Platform

Your organization operates a multi-tier application on Google Cloud, consisting of a frontend hosted on Cloud Run and a backend hosted on Compute Engine. You need to design the network to prevent unauthorized data exfiltration while ensuring the frontend can communicate with the backend. Which of the following steps should you take to meet the requirements?

  1. A

    Use VPC Service Controls to define a service perimeter around the backend resources.

  2. B

    Configure private Google access for the Compute Engine instances hosting the backend.

  3. C

    Apply egress firewall rules to the Compute Engine instances to restrict traffic to specific destinations.

  4. D

    Enable Cloud NAT to allow the backend to access the internet for updates.

  5. E

    Deploy the frontend and backend in different VPCs to isolate traffic.

Show answer and explanation

Correct answers: A, C

Explanation

To prevent data exfiltration while ensuring communication between the frontend and backend, you should use VPC Service Controls to define a security perimeter and apply egress firewall rules to restrict outgoing traffic. These steps help minimize unauthorized access and limit the destinations where data can be sent.

  • A. Correct.

    VPC Service Controls help create a security perimeter for services and resources, reducing the risk of unauthorized data exfiltration.

  • B. Incorrect.

    Private Google access is used to allow internal resources to access Google APIs and services, but it does not directly prevent data exfiltration.

  • C. Correct.

    Egress firewall rules enable you to restrict outgoing traffic from the Compute Engine instances, thereby helping to prevent unauthorized data exfiltration.

  • D. Incorrect.

    Cloud NAT allows instances to access the internet without exposing them externally, but it is not directly related to data exfiltration prevention.

  • E. Incorrect.

    Deploying the frontend and backend in different VPCs adds complexity and is not required for this scenario, as communication between tiers can be secured using firewall rules and service accounts.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam