Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your organization hosts a sensitive internal administrative web application on Google Kubernetes Engine (GKE) behind an External HTTP(S) Load Balancer, along with private Compute Engine virtual machines (VMs) that administrators manage using SSH.
Your security team mandates the following requirements:
Which architecture should you implement?
Deploy a dedicated bastion host with a public IP address in a perimeter subnet, enforce OS Login with 2-step verification for SSH access, and configure VPC firewall rules to restrict traffic to corporate office CIDR ranges.
Configure Google Cloud Armor security policies on the External HTTP(S) Load Balancer with geo-blocking rules, and assign the Compute OS Admin Login role to administrators for direct VM access.
Deploy a Cloud VPN gateway between remote worker environments and the VPC, configure private DNS zones, and restrict access using subnet-level Network Security Groups and IAM permissions.
Enable Identity-Aware Proxy (IAP) on the load balancer backend service and use IAP TCP forwarding for VM SSH access. Define access levels in Access Context Manager using Chrome Enterprise Premium device posture and geographic criteria, and enforce them using IAM conditions.
Deploy a dedicated bastion host with a public IP address in a perimeter subnet, enforce OS Login with 2-step verification for SSH access, and configure VPC firewall rules to restrict traffic to corporate office CIDR ranges.
Configure Google Cloud Armor security policies on the External HTTP(S) Load Balancer with geo-blocking rules, and assign the Compute OS Admin Login role to administrators for direct VM access.
Deploy a Cloud VPN gateway between remote worker environments and the VPC, configure private DNS zones, and restrict access using subnet-level Network Security Groups and IAM permissions.
Enable Identity-Aware Proxy (IAP) on the load balancer backend service and use IAP TCP forwarding for VM SSH access. Define access levels in Access Context Manager using Chrome Enterprise Premium device posture and geographic criteria, and enforce them using IAM conditions.
Identity-Aware Proxy (IAP) provides a zero-trust application and administrative access layer by establishing identity-centric controls instead of traditional network-level perimeters. In conjunction with Access Context Manager and Chrome Enterprise Premium, IAP evaluates contextual signals—such as identity, geographic location, and device security posture—before proxying any traffic to backend services.
nic0), removing the need for external IPs on Compute Engine instances.request.auth.access_levels), ensures only compliant corporate devices from authorized regions gain access.This approach directly satisfies all zero-trust criteria without introducing complex network routing, custom reverse proxies, or dedicated jump hosts.