Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is deploying a fleet of private Compute Engine instances without external IP addresses into a dedicated Virtual Private Cloud (VPC) subnet. The security team has defined the following security, routing, and observability requirements:
Which combination of architectural configurations and observability controls should the security engineer implement?
This architecture combines Private Google Access (PGA), Cloud NAT, Cloud Next Generation Firewall (Cloud NGFW) policies, Cloud NAT logging, and Cloud Monitoring alerting to deliver secure outbound internet connectivity, optimize Google API routing, enforce pre-translation firewall filtering, and provide robust telemetry.
ALL) captures both established outbound connections and dropped packets caused by port exhaustion in Cloud Logging. Creating an alerting policy on the nat_allocation_failed metric in Cloud Monitoring ensures real-time notification when workloads run out of available NAT ports.This approach leverages fully managed, cloud-native services that scale horizontally while maintaining strict least-privilege boundary controls and full observability across all outbound network flows.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.