Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 219 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 219

Select 2Google Cloud Platform

Your organization needs to deploy a secure web proxy to filter and inspect outgoing web traffic from workloads running in Google Cloud. The solution must ensure that all traffic is routed through the proxy while maintaining high availability and scalability. Which combination of steps should you follow to achieve this?

  1. A

    Deploy a managed instance group (MIG) with a fleet of proxy servers and configure them with a load balancer.

  2. B

    Set up Cloud NAT to route traffic from the workloads to the internet through the proxy servers.

  3. C

    Configure VPC firewall rules to allow instances to communicate only with the secure web proxy.

  4. D

    Enable private Google access on the subnet where the workloads are deployed.

  5. E

    Use VPC Service Controls to enforce traffic routing through the secure web proxy.

Show answer and explanation

Correct answers: A, C

Explanation

To deploy a secure web proxy in Google Cloud, you must ensure that all traffic from workloads is routed through the proxy while maintaining high availability and scalability. A managed instance group (MIG) with load balancing provides a scalable and highly available fleet of proxy servers. VPC firewall rules are necessary to restrict instances from bypassing the proxy and ensure secure traffic inspection. Other options, like Cloud NAT or VPC Service Controls, do not provide the required functionality for enforcing proxy usage.

  • A. Correct.

    This is correct. Deploying a managed instance group (MIG) ensures high availability and scalability for the proxy servers, and a load balancer distributes traffic across the proxy fleet.

  • B. Incorrect.

    This is incorrect. Cloud NAT is used for outbound internet access without external IPs, but it cannot enforce traffic routing through a proxy.

  • C. Correct.

    This is correct. Configuring VPC firewall rules ensures that instances can only communicate with the secure web proxy, preventing bypass.

  • D. Incorrect.

    This is incorrect. Private Google access allows instances to access Google APIs and services privately but does not enforce traffic routing through a proxy.

  • E. Incorrect.

    This is incorrect. VPC Service Controls provide perimeter security for Google Cloud services but are not used to enforce traffic routing through a web proxy.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam