Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise is migrating multi-terabyte datasets containing sensitive customer records from an on-premises data center to Google Cloud. The compliance and security team has mandated the following requirements for data transit:
Which solution should the enterprise implement?
Establish VPC Network Peering directly between the on-premises router and the VPC, and assign strict Identity and Access Management (IAM) storage roles.
Deploy standard HA VPN gateways over the public internet across two regions, and configure VPC firewall rules to block egress to non-approved IP addresses.
Provision Partner Interconnect Layer 2 connections with standard unencrypted VLAN attachments, and deploy Cloud Armor security policies on the target VPC.
Deploy Dedicated Interconnect across two regions with encrypted VLAN attachments and HA VPN, and configure a VPC Service Controls perimeter around the target cloud resources.
Establish VPC Network Peering directly between the on-premises router and the VPC, and assign strict Identity and Access Management (IAM) storage roles.
Deploy standard HA VPN gateways over the public internet across two regions, and configure VPC firewall rules to block egress to non-approved IP addresses.
Provision Partner Interconnect Layer 2 connections with standard unencrypted VLAN attachments, and deploy Cloud Armor security policies on the target VPC.
Deploy Dedicated Interconnect across two regions with encrypted VLAN attachments and HA VPN, and configure a VPC Service Controls perimeter around the target cloud resources.
Dedicated Interconnect with HA VPN (HA VPN over Cloud Interconnect) combines the high-throughput, low-latency private physical transport of Google Cloud Dedicated Interconnect with network-layer IPsec encryption. VPC Service Controls establishes a secure isolation boundary (service perimeter) around Google Cloud managed services such as Cloud Storage and BigQuery to mitigate data exfiltration risks.
This approach directly satisfies all bandwidth, high-availability, encryption-in-transit, and perimeter-level data exfiltration requirements simultaneously, whereas standard interconnect or internet VPN solutions fail to meet one or more of these criteria.