Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organization implements a hub-and-spoke network architecture in Google Cloud. The architecture includes a centralized hub-vpc connected to an on-premises data center using Cloud Interconnect, and a separate spoke-vpc hosting application workloads. The two VPCs are interconnected using VPC Network Peering.
The security and network engineering teams have established the following requirements:
spoke-vpc through hub-vpc.hub-vpc must advertise the spoke-vpc address spaces to the on-premises Border Gateway Protocol (BGP) peers.hub-vpc must restrict incoming traffic based on the identity of workloads running in spoke-vpc without using IP CIDR blocks or non-functional cross-peering constructs.Which combination of routing configurations and firewall controls should the organization implement?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.