Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your organization is establishing shared networking across multiple Google Cloud projects. A producer team has deployed a microservice behind an internal load balancer and exposed it using a Private Service Connect (PSC) service attachment.
Your DevOps team needs to configure connectivity from a consumer VPC network while meeting the following requirements:
Which configuration should the DevOps team implement in the consumer network?
Create a Cloud DNS forwarding zone to query Service Directory, and attach Cloud Armor policies to the Service Directory endpoint.
Create a Private Service Connect network endpoint group (NEG) pointing to the service attachment URI, and configure it as a backend for an internal Application Load Balancer.
Configure Private Services Access with an allocated IP range, and establish a VPC Network Peering connection to the producer network.
Create a Private Service Connect endpoint forwarding rule pointing directly to the service attachment URI, and attach a Cloud Armor security policy to the forwarding rule.
Create a Cloud DNS forwarding zone to query Service Directory, and attach Cloud Armor policies to the Service Directory endpoint.
Create a Private Service Connect network endpoint group (NEG) pointing to the service attachment URI, and configure it as a backend for an internal Application Load Balancer.
A Private Service Connect (PSC) backend utilizes a specialized PSC network endpoint group (NEG) that targets the producer's service attachment URI. This configuration allows an Application Load Balancer (internal or external regional) in the consumer network to treat the producer's published service as a standard backend service.
A PSC backend with a PSC NEG is the only Google Cloud architectural pattern that combines the private isolation of Private Service Connect with the Layer 7 capabilities, Cloud Armor integration, and fine-grained request decoration of Application Load Balancers.
Configure Private Services Access with an allocated IP range, and establish a VPC Network Peering connection to the producer network.
Create a Private Service Connect endpoint forwarding rule pointing directly to the service attachment URI, and attach a Cloud Armor security policy to the forwarding rule.