Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 283 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 283

Single answerGoogle Cloud Platform

You are designing a network architecture for a web application hosted on Google Cloud. The application instances are deployed in a private subnet within a VPC. The application needs to fetch data from an external API over the internet, but you must ensure that the instances do not have public IP addresses. How can you achieve this requirement?

  1. A

    Configure Cloud NAT for the private subnet to enable internet access for the instances.

  2. B

    Assign public IP addresses to the instances and use a firewall rule to allow outbound traffic.

  3. C

    Use a VPN to route the traffic from the private instances to the external API.

  4. D

    Set up a proxy server in a public subnet to forward traffic from private instances to the internet.

Show answer and explanation

Correct answer: A

Explanation

Cloud NAT (Network Address Translation) allows private instances in a VPC to access external resources on the internet for outbound traffic without requiring public IP addresses. This ensures that the instances remain secure and do not directly expose themselves to the internet. It is the most straightforward solution to meet the given requirements.

  • A. Correct.

    This is the correct solution. Cloud NAT allows instances in a private subnet to access the internet for outbound traffic without requiring public IP addresses.

  • B. Incorrect.

    This is incorrect because assigning public IP addresses violates the requirement to avoid public IPs and exposes the instances to the internet, which is a security risk.

  • C. Incorrect.

    This is incorrect because a VPN is not necessary to access external APIs over the internet and does not address the need for secure outbound traffic from private instances.

  • D. Incorrect.

    This is incorrect because while a proxy server could work, it adds unnecessary complexity compared to using Cloud NAT, which is specifically designed for this purpose.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam