Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 242 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 242

Select 2Google Cloud Platform

Your organization has a multi-project architecture in Google Cloud. You have been tasked with configuring secure communication between services in two separate projects: Project-A and Project-B. The services in these projects need to communicate over internal IPs only, and you want to ensure that firewall rules are correctly configured. Both projects are part of the same organization. Which steps should you take to achieve this setup?

  1. A

    Set up VPC Peering between the VPC networks in Project-A and Project-B.

  2. B

    Configure a Shared VPC where Project-A and Project-B are service projects, and use a host project to manage the VPC network.

  3. C

    Create a firewall rule to allow ingress traffic between the VPC networks in Project-A and Project-B.

  4. D

    Ensure that the subnets in Project-A and Project-B do not have overlapping IP ranges.

  5. E

    Use Cloud VPN to establish a secure connection between the two projects.

Show answer and explanation

Correct answers: A, D

Explanation

To enable secure internal IP communication between services in two separate projects, you should configure VPC Peering between their respective VPC networks. Additionally, it is critical to ensure that the subnets in these VPC networks do not have overlapping IP ranges, as this is a prerequisite for VPC Peering. Shared VPC and Cloud VPN are not required for this scenario, and additional firewall rules are unnecessary because VPC Peering automatically allows traffic over internal IPs.

  • A. Correct.

    Setting up VPC Peering allows the VPC networks in Project-A and Project-B to communicate over internal IPs without traversing the public internet. This is required for secure communication.

  • B. Incorrect.

    Shared VPC is not necessary in this case since the requirement is to enable communication between two separate projects, not to consolidate networking resources under a single host project.

  • C. Incorrect.

    Firewall rules are configured at the VPC level, but VPC Peering automatically allows internal IP communication between peered networks, so no additional ingress rules are needed for this scenario.

  • D. Correct.

    Ensuring that the subnets do not have overlapping IP ranges is a prerequisite for VPC Peering to work correctly. Overlapping IPs would cause routing conflicts.

  • E. Incorrect.

    Cloud VPN is not needed in this case because VPC Peering already enables secure internal IP communication between the two networks without requiring additional tunneling.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam