Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise requires on-premises workloads to privately access Google Cloud APIs and services without routing traffic over the public internet. The on-premises data center is connected to a Google Cloud Virtual Private Cloud (VPC) network via Cloud Interconnect. To comply with security policies, the API communication must be restricted to services supported by VPC Service Controls.
Which combination of DNS and routing configurations should the enterprise implement?
Configure on-premises DNS to resolve *.googleapis.com CNAME records to restricted.googleapis.com (199.36.153.4/30), and configure custom BGP route advertisements on the VPC's Cloud Router to announce 199.36.153.4/30 to on-premises routers.
Configure on-premises DNS to resolve *.googleapis.com CNAME records to default.googleapis.com, and advertise a default route (0.0.0.0/0) from the VPC Cloud Router to on-premises routers.
Enable Private Google Access on the VPC subnets, deploy a Cloud NAT gateway, and advertise the Cloud NAT external IP addresses over BGP to the on-premises network.
Configure on-premises DNS to resolve *.googleapis.com to private.googleapis.com (199.36.153.8/30), and enable custom route exports via VPC Network Peering to transitively forward the routes to on-premises routers.
Configure on-premises DNS to resolve *.googleapis.com CNAME records to restricted.googleapis.com (199.36.153.4/30), and configure custom BGP route advertisements on the VPC's Cloud Router to announce 199.36.153.4/30 to on-premises routers.
Private Google Access for on-premises hosts provides private connectivity from hybrid environments (such as on-premises data centers or colocation facilities connected via Cloud Interconnect or Cloud VPN) directly to Google APIs and services using internal Google network paths rather than the public internet.
*.googleapis.com domains to restricted.googleapis.com directs traffic to the dedicated IP range 199.36.153.4/30. This special virtual IP (VIP) block allows access exclusively to Google services that support VPC Service Controls, blocking unverified or unsupported services.199.36.153.4/30 ensures on-premises routers have an explicit route pointing to the Cloud Interconnect / Cloud VPN gateway for all Google API destinations.Using restricted.googleapis.com (199.36.153.4/30) combined with custom BGP route advertisements natively aligns hybrid routing topology with perimeter security controls, satisfying all security and zero-internet transit requirements.
Configure on-premises DNS to resolve *.googleapis.com CNAME records to default.googleapis.com, and advertise a default route (0.0.0.0/0) from the VPC Cloud Router to on-premises routers.
Enable Private Google Access on the VPC subnets, deploy a Cloud NAT gateway, and advertise the Cloud NAT external IP addresses over BGP to the on-premises network.
Configure on-premises DNS to resolve *.googleapis.com to private.googleapis.com (199.36.153.8/30), and enable custom route exports via VPC Network Peering to transitively forward the routes to on-premises routers.