Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise maintains a hybrid architecture connecting an on-premises data center to a Google Cloud Virtual Private Cloud (VPC) over Cloud Interconnect. The organization has established the following security and networking requirements for name resolution:
Which Cloud DNS design and policy configuration should the security engineer implement to satisfy these requirements?
Deploy a Cloud Service Mesh Envoy proxy layer with auto-capacity draining to route port 53 UDP/TCP traffic across Cloud Interconnect, and configure Cloud Armor security policies on the proxies.
Create a Cloud DNS server policy attached to the VPC with inbound query forwarding enabled, configure outbound private forwarding zones to direct on-premises domain queries to the on-premises DNS servers, and enable Cloud DNS query logging on the VPC network.
Deploy a global external Application Load Balancer with Cloud DNS failover routing policies to route on-premises DNS traffic, and configure VPC Flow Logs with a 100% sample rate.
Configure a Packet Mirroring policy targeting an internal passthrough Network Load Balancer collector pool to inspect port 53 traffic, and configure custom iptables DNAT rules on each VM to redirect DNS queries to on-premises servers.
Deploy a Cloud Service Mesh Envoy proxy layer with auto-capacity draining to route port 53 UDP/TCP traffic across Cloud Interconnect, and configure Cloud Armor security policies on the proxies.
Create a Cloud DNS server policy attached to the VPC with inbound query forwarding enabled, configure outbound private forwarding zones to direct on-premises domain queries to the on-premises DNS servers, and enable Cloud DNS query logging on the VPC network.
Cloud DNS Server Policies and DNS Query Logging provide centralized management and visibility over internal DNS resolution across Google Cloud VPC networks and connected hybrid environments. A server policy allows administrators to control inbound and outbound DNS traffic pathways for all Compute Engine workloads within a VPC network, while query logging captures end-to-end DNS activity for threat analysis.
/etc/resolv.conf or guest operating system settings.This architecture uses native Google Cloud networking constructs to achieve fully bidirectional private name resolution while ensuring complete logging visibility across all hybrid resolution paths.
Deploy a global external Application Load Balancer with Cloud DNS failover routing policies to route on-premises DNS traffic, and configure VPC Flow Logs with a 100% sample rate.
Configure a Packet Mirroring policy targeting an internal passthrough Network Load Balancer collector pool to inspect port 53 traffic, and configure custom iptables DNAT rules on each VM to redirect DNS queries to on-premises servers.