Google Professional Cloud Security Engineer Question 271
Select 2Google Cloud PlatformYour organization requires secure, high-throughput private connectivity between an on-premises data center and a Google Cloud VPC network. The solution must support encryption in transit, high availability, and minimal latency for critical workloads. Which combination of Google Cloud services would best meet these requirements?
- A
Cloud Interconnect with IPsec encryption using HA VPN
- B
Cloud VPN (Classic VPN) with a single tunnel
- C
Dedicated Interconnect with Customer-Managed Encryption (CMEK)
- D
Partner Interconnect with IPsec encryption using HA VPN
- E
Peering over the public internet with mutual TLS for encryption
Show answer and explanation
Correct answers: A, D
Explanation
To achieve secure, high-throughput private connectivity between an on-premises data center and a Google Cloud VPC network, using Cloud Interconnect combined with HA VPN or Partner Interconnect with HA VPN ensures encryption in transit, high availability, and minimal latency. Both solutions are robust and meet the organization's requirements for critical workload connectivity.
- A. Correct.
Cloud Interconnect combined with IPsec encryption using HA VPN provides a secure and high-throughput solution, ensuring private connectivity with encryption in transit and high availability. This meets the organization's requirements for security, throughput, and reliability.
- B. Incorrect.
Cloud VPN (Classic VPN) with a single tunnel does not provide sufficient throughput or high availability for critical workloads. Classic VPN also lacks the scalability and robustness needed for enterprise-grade solutions.
- C. Incorrect.
Dedicated Interconnect with CMEK can provide high throughput and private connectivity, but it does not inherently support encryption in transit. Additional configurations would be required to meet the encryption requirement, making it less suitable compared to other options.
- D. Correct.
Partner Interconnect with IPsec encryption using HA VPN is a suitable solution for organizations that prefer working with a connectivity partner. It provides a secure, encrypted connection with high availability, meeting the requirements for security and throughput.
- E. Incorrect.
Peering over the public internet with mutual TLS does not meet the requirement for private connectivity and may introduce latency and security risks, making it unsuitable for critical workloads.