Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is designing a secure three-tier application architecture on Google Cloud across isolated VPC networks for the presentation tier, business logic tier, and database tier. The security team establishes the following boundary isolation requirements:
Which combination of network isolation and data encapsulation controls should you deploy?
This architecture combines Private Service Connect (PSC), Internal Application Load Balancers (Envoy-based L7 ILBs) with dedicated proxy-only subnets, and Private Google Access to enforce zero-trust boundary segmentation and complete data encapsulation for multi-tier applications.
purpose=REGIONAL_MANAGED_PROXY) to handle proxying and header inspection without exposing workload IP addresses.This architecture strictly isolates each tier's fault domain and network perimeter while providing line-rate performance and comprehensive Layer 7 traffic management.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.