Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 18 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 18

Select 2Google Cloud Platform

Your organization processes sensitive financial data in Google Cloud and needs to design a network architecture to minimize the risk of data exfiltration. The architecture must ensure that only trusted Google Cloud services can communicate with your Virtual Private Cloud (VPC) resources, while all other external traffic is blocked by default. How can you best achieve this requirement?

  1. A

    Use VPC Service Controls to define service perimeters around your sensitive resources.

  2. B

    Configure Private Google Access to allow instances in your VPC to securely connect to Google APIs and services.

  3. C

    Enable a Cloud NAT gateway to give outbound internet connectivity to your instances without exposing their private IPs.

  4. D

    Set up a firewall rule to allow traffic only from specific IP ranges belonging to trusted third-party services.

  5. E

    Deploy a Cloud Armor policy to block all incoming traffic from external sources.

Show answer and explanation

Correct answers: A, B

Explanation

To minimize the risk of data exfiltration while ensuring secure communication with trusted Google Cloud services, combining VPC Service Controls and Private Google Access is the best solution. VPC Service Controls create service perimeters that restrict access to sensitive resources, and Private Google Access allows instances to securely access Google APIs and services without relying on public internet connectivity. Other options either do not meet the core requirement of restricting traffic to trusted Google services or address unrelated concerns.

  • A. Correct.

    VPC Service Controls can define service perimeters to prevent data exfiltration by ensuring resources are accessed only from trusted environments. This directly addresses the requirement to secure sensitive data.

  • B. Correct.

    Enabling Private Google Access allows your VPC instances to securely access Google APIs and services without requiring external internet connectivity, thereby reducing the risk of data exfiltration.

  • C. Incorrect.

    A Cloud NAT gateway provides external connectivity without exposing private IPs, but it does not restrict access to only trusted Google Cloud services, which is a core requirement of this scenario.

  • D. Incorrect.

    A firewall rule restricting traffic by IP ranges can help control access, but it does not specifically enforce communication with only trusted Google Cloud services.

  • E. Incorrect.

    Cloud Armor policies are designed for protecting applications and services from external threats, but they do not address the requirement to prevent data exfiltration by restricting access to trusted Google services.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam