Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is deploying a fleet of private Compute Engine instances without external IP addresses into a dedicated Virtual Private Cloud (VPC) subnet. The security team has defined the following security, routing, and observability requirements:
Which combination of architectural configurations and observability controls should the security engineer implement?
Enable Private Google Access on the subnet, deploy a regional Cloud NAT gateway configured for the subnet, define egress Cloud NGFW rules targeting the VM internal IP addresses, enable Cloud NAT logging with 'Translation and errors' selected, and configure a Cloud Monitoring alert policy on the 'nat_allocation_failed' metric.
Configure a VPC Service Controls perimeter bridge to route internet traffic, create a Cloud NAT gateway logging 'Translations only', define hierarchical firewall rules using destination FQDNs, and create a Cloud Logging export sink to Pub/Sub to trigger a Cloud Run function for alert generation.
Deploy Cloud NAT with static manual IP addresses, delete the default internet gateway route, enable VPC Flow Logs with 15-minute aggregation intervals, write ingress firewall rules permitting NAT responses, and configure Pub/Sub alerts via Cloud Asset Inventory notifications.
Configure Private Services Access with a peering range, deploy Cloud NAT with automatic IP allocation, write egress firewall rules matching the Cloud NAT external IP addresses, enable Cloud NAT logging for 'Errors only', and create a Cloud Monitoring alert on the 'nat_ports_used' metric.
Enable Private Google Access on the subnet, deploy a regional Cloud NAT gateway configured for the subnet, define egress Cloud NGFW rules targeting the VM internal IP addresses, enable Cloud NAT logging with 'Translation and errors' selected, and configure a Cloud Monitoring alert policy on the 'nat_allocation_failed' metric.
This architecture combines Private Google Access (PGA), Cloud NAT, Cloud Next Generation Firewall (Cloud NGFW) policies, Cloud NAT logging, and Cloud Monitoring alerting to deliver secure outbound internet connectivity, optimize Google API routing, enforce pre-translation firewall filtering, and provide robust telemetry.
ALL) captures both established outbound connections and dropped packets caused by port exhaustion in Cloud Logging. Creating an alerting policy on the nat_allocation_failed metric in Cloud Monitoring ensures real-time notification when workloads run out of available NAT ports.This approach leverages fully managed, cloud-native services that scale horizontally while maintaining strict least-privilege boundary controls and full observability across all outbound network flows.
Configure a VPC Service Controls perimeter bridge to route internet traffic, create a Cloud NAT gateway logging 'Translations only', define hierarchical firewall rules using destination FQDNs, and create a Cloud Logging export sink to Pub/Sub to trigger a Cloud Run function for alert generation.
Deploy Cloud NAT with static manual IP addresses, delete the default internet gateway route, enable VPC Flow Logs with 15-minute aggregation intervals, write ingress firewall rules permitting NAT responses, and configure Pub/Sub alerts via Cloud Asset Inventory notifications.
Configure Private Services Access with a peering range, deploy Cloud NAT with automatic IP allocation, write egress firewall rules matching the Cloud NAT external IP addresses, enable Cloud NAT logging for 'Errors only', and create a Cloud Monitoring alert on the 'nat_ports_used' metric.