Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial enterprise is designing a network architecture on Google Cloud to adhere to strict regulatory compliance standards for sensitive data workloads. The organization must meet the following security requirements:
Which combination of Google Cloud architectural controls should the enterprise implement?
This architecture combines VPC Service Controls, Private Google Access via the restricted.googleapis.com virtual IP (VIP) address range, Google Cloud Armor edge security policies on an external Application Load Balancer, and Identity-Aware Proxy (IAP) TCP forwarding to form a layered defense-in-depth perimeter for regulatory compliance.
*.googleapis.com DNS zone to restricted.googleapis.com (which resolves to 199.36.153.4/30) ensures that internal VMs communicate with supported Google APIs across private routes and blocks access to unmanaged public services.35.191.0.0/16, 130.211.0.0/22).22 using Google-managed authentication without external IP addresses.This approach aligns with Google Cloud security best practices by implementing segmentation across all four critical planes: data API boundaries, private egress routing, public ingress edge inspection, and identity-aware management channels.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.