Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Your enterprise operates a hybrid CI/CD pipeline where deployment runners in an on-premises data center deploy containerized workloads to on-premises Anthos/GKE Enterprise clusters. The on-premises environment connects to your Google Cloud Virtual Private Cloud (VPC) through Dedicated Cloud Interconnect.
You need to design a secure deployment workflow that satisfies the following requirements:
Which combination of architectural patterns and services should you implement?
Private Google Access for on-premises hosts allows external networks connected via Cloud Interconnect or Cloud VPN to resolve and reach Google APIs and services—such as Artifact Registry and Secret Manager—using internal RFC 1918 or private VIP routing (private.googleapis.com or restricted.googleapis.com), completely avoiding internet transit. Workload Identity Federation allows non-Google Cloud compute workloads (such as on-premises CI/CD runners or Kubernetes pods) to use their native identity providers (such as OpenID Connect or SAML) to obtain short-lived Google Cloud credentials dynamically.
Combining Private Google Access over Cloud Interconnect with Workload Identity Federation adheres strictly to Google Cloud security architecture best practices for hybrid pipelines, mitigating risks of credential theft and data exfiltration while keeping all traffic on private channels.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.