Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization is deploying an internet-facing web service on Compute Engine instances in Google Cloud. The security and compliance teams have defined the following technical and architectural requirements:
europe-west3 region; terminating TLS at globally distributed edge points of presence (PoPs) is prohibited.Which load balancing architecture should the security engineer deploy to satisfy all requirements?
Deploy a Regional external Application Load Balancer in europe-west3, reserve a regional proxy-only subnet in the VPC, and attach a regional SSL certificate and regional URL map.
Deploy an External passthrough Network Load Balancer in europe-west3 with a regional backend service and configure an SSL target proxy.
Deploy a Regional external proxy Network Load Balancer in europe-west3, reserve a proxy-only subnet, and configure an SSL target proxy with advanced URL maps.
Deploy a Global external Application Load Balancer in Premium Tier with backends in europe-west3, and configure a global SSL certificate and global URL map.
Deploy a Regional external Application Load Balancer in europe-west3, reserve a regional proxy-only subnet in the VPC, and attach a regional SSL certificate and regional URL map.
A Regional external Application Load Balancer is a regional, proxy-based Layer 7 load balancer built on managed open-source Envoy proxies. It distributes external HTTP and HTTPS traffic to backend services situated in a single specific Google Cloud region while supporting advanced traffic management and security features.
europe-west3), ensuring complete compliance with data sovereignty and geographic isolation mandates.REGIONAL_MANAGED_PROXY) to connect to backend VMs.Compared to global load balancers, the regional external Application Load Balancer isolates all proxy execution, cryptographic operations, and Layer 7 processing to the specified region (europe-west3), perfectly aligning with regulatory mandates while providing complete HTTP(S) routing capabilities.
Deploy an External passthrough Network Load Balancer in europe-west3 with a regional backend service and configure an SSL target proxy.
Deploy a Regional external proxy Network Load Balancer in europe-west3, reserve a proxy-only subnet, and configure an SSL target proxy with advanced URL maps.
Deploy a Global external Application Load Balancer in Premium Tier with backends in europe-west3, and configure a global SSL certificate and global URL map.