Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A Cloud Solutions Architect is using natural language prompts in Gemini Cloud Assist to generate Terraform Infrastructure as Code (IaC) and deployment scripts for a secure internal workload on Compute Engine.
The organizational security policy dictates the following technical requirements:
default VPC network.Which infrastructure architecture and configuration generated by Gemini Cloud Assist meets all organizational technical and security requirements while adhering to Google Cloud best practices?
Generate Terraform utilizing the terraform-google-project-factory module to create resources within the default VPC, configure private Google access only, and grant roles/compute.imageUser to allAuthenticatedUsers.
Generate Terraform defining a custom VPC network and subnet, configure a Cloud Router with Cloud NAT, attach a dedicated service account to the VM instance template, and omit the access_config block from the VM network interface.
Generate Terraform defining a custom VPC network and subnet, assign an access_config block configured with External NAT to the network interface, and assign the roles/compute.admin role to the default Compute Engine service account.
Generate a gcloud script that provisions instances within the project's default VPC network, attaches Cloud NAT to the default gateway, and configures an instance template with the default service account and cloud-platform access scope.
Generate Terraform utilizing the terraform-google-project-factory module to create resources within the default VPC, configure private Google access only, and grant roles/compute.imageUser to allAuthenticatedUsers.
Generate Terraform defining a custom VPC network and subnet, configure a Cloud Router with Cloud NAT, attach a dedicated service account to the VM instance template, and omit the access_config block from the VM network interface.
This solution uses Gemini Cloud Assist to generate Terraform Infrastructure as Code (IaC) that establishes an enterprise-grade, secure private compute architecture adhering to the Google Cloud Well-Architected Framework.
access_config block inside network_interface ensures that the VM instances are provisioned without an external (public) IP address.This approach directly satisfies every security requirement while adopting standard Google Cloud best practices for network isolation, controlled egress, and identity governance.
Generate Terraform defining a custom VPC network and subnet, assign an access_config block configured with External NAT to the network interface, and assign the roles/compute.admin role to the default Compute Engine service account.
Generate a gcloud script that provisions instances within the project's default VPC network, attaches Cloud NAT to the default gateway, and configures an instance template with the default service account and cloud-platform access scope.