Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is deploying backend application workloads on Compute Engine virtual machine (VM) instances in a dedicated subnet. For security compliance, the VMs are configured with only internal RFC 1918 IP addresses and must remain isolated from unsolicited inbound internet traffic.
The workload architecture has the following egress requirements:
Which combination of network configurations should you implement to satisfy these requirements?
Assign ephemeral external IP addresses to each VM and attach Google Cloud Armor security policies directly to the Compute Engine instances.
Configure VPC Network Peering to Google APIs and establish an external Application Load Balancer to proxy outbound SaaS requests.
Enable Private Google Access on the subnet and deploy a Cloud NAT gateway in the corresponding region.
Create Private Service Connect endpoints for the third-party SaaS API and configure Hybrid NAT for Google APIs.
Assign ephemeral external IP addresses to each VM and attach Google Cloud Armor security policies directly to the Compute Engine instances.
Configure VPC Network Peering to Google APIs and establish an external Application Load Balancer to proxy outbound SaaS requests.
Enable Private Google Access on the subnet and deploy a Cloud NAT gateway in the corresponding region.
Private Google Access (PGA) is a VPC subnet-level feature that enables VM instances without external IP addresses to reach the external IP addresses of Google APIs and services over Google's internal network backbone. Cloud NAT (Network Address Translation) is a distributed, software-defined managed service that enables instances without external IP addresses to send outbound packets to the internet while preventing external hosts from initiating direct inbound sessions.
This approach leverages native, fully managed Google Cloud networking services that scale automatically with workload demand, require zero VM re-architecting, and strictly adhere to the principle of least exposure.
Create Private Service Connect endpoints for the third-party SaaS API and configure Hybrid NAT for Google APIs.