Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise requires on-premises workloads to privately access Google Cloud APIs and services without routing traffic over the public internet. The on-premises data center is connected to a Google Cloud Virtual Private Cloud (VPC) network via Cloud Interconnect. To comply with security policies, the API communication must be restricted to services supported by VPC Service Controls.
Which combination of DNS and routing configurations should the enterprise implement?
Private Google Access for on-premises hosts provides private connectivity from hybrid environments (such as on-premises data centers or colocation facilities connected via Cloud Interconnect or Cloud VPN) directly to Google APIs and services using internal Google network paths rather than the public internet.
*.googleapis.com domains to restricted.googleapis.com directs traffic to the dedicated IP range 199.36.153.4/30. This special virtual IP (VIP) block allows access exclusively to Google services that support VPC Service Controls, blocking unverified or unsupported services.199.36.153.4/30 ensures on-premises routers have an explicit route pointing to the Cloud Interconnect / Cloud VPN gateway for all Google API destinations.Using restricted.googleapis.com (199.36.153.4/30) combined with custom BGP route advertisements natively aligns hybrid routing topology with perimeter security controls, satisfying all security and zero-internet transit requirements.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.