Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial enterprise is securing its Google Cloud environment to minimize perimeter attack surfaces and prevent unintended internet exposure. The security architect establishes the following requirements:
Which combination of architectural controls and services should the security architect deploy?
This architecture combines preventive organizational governance, edge translation, zero-trust administrative access, and managed reverse-proxy ingress to isolate virtual machines entirely within private IP address spaces while retaining full outbound capability, secure management, and public service delivery.
constraints/compute.vmExternalIpAccess) organization policy constraint with a policy value of Deny All replaces default behaviors and blocks any Compute Engine instance in the organization from acquiring public external IP addresses.35.235.240.0/20 allows authenticated, authorized administrators to access VMs without assigning public IPs or running dedicated bastion hosts.This pattern aligns with defense-in-depth and zero-trust principles by ensuring that compute resources never maintain direct public IP bindings while cleanly separating inbound reverse-proxy edge routing, outbound egress translation, and IAM-gated administrative access.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.