Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is migrating sensitive internal web applications and Compute Engine instances to Google Cloud. The security team needs to implement a Zero Trust access architecture that meets the following criteria:
Which architecture should you implement to satisfy these requirements?
Deploy an external Application Load Balancer with Google Cloud Armor IP allowlists, delegate privileges using service account keys stored on developer endpoints, and rely on Security Command Center Event Threat Detection.
Deploy a dedicated bastion host VM with an external IP address, restrict incoming traffic using VPC firewall rules based on source IP CIDRs, and monitor user connections using default Cloud Audit Logs Admin Activity logs.
Configure Identity-Aware Proxy (IAP) for internal web apps and IAP TCP forwarding for SSH, enforce device posture using Access Context Manager access levels applied through IAM conditions, and enable Cloud Audit Logs Data Access logging.
Provision a Cloud VPN gateway to connect developer workstations to the VPC, grant the Compute OS Admin Login role permanently to all developers, and capture network activity with VPC Flow Logs.
Deploy an external Application Load Balancer with Google Cloud Armor IP allowlists, delegate privileges using service account keys stored on developer endpoints, and rely on Security Command Center Event Threat Detection.
Deploy a dedicated bastion host VM with an external IP address, restrict incoming traffic using VPC firewall rules based on source IP CIDRs, and monitor user connections using default Cloud Audit Logs Admin Activity logs.
Configure Identity-Aware Proxy (IAP) for internal web apps and IAP TCP forwarding for SSH, enforce device posture using Access Context Manager access levels applied through IAM conditions, and enable Cloud Audit Logs Data Access logging.
This architecture combines Identity-Aware Proxy (IAP), Access Context Manager (ACM), and Cloud Audit Logs to establish a comprehensive Zero Trust access model for Google Cloud resources.
This approach aligns with Google Cloud security best practices by implementing identity-centric security, zero network exposure, and continuous compliance auditing.
Provision a Cloud VPN gateway to connect developer workstations to the VPC, grant the Compute OS Admin Login role permanently to all developers, and capture network activity with VPC Flow Logs.