Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise is securing communications between its Google Cloud VPC network and Google APIs to prevent data exfiltration. The security architect has established the following requirements:
Which combination of private connectivity architectures should the architect implement?
Configure Cloud DNS to resolve *.googleapis.com to private.googleapis.com (199.36.153.8/30) for the entire VPC, and create a Private Services Access (PSA) connection for the analytics subnet.
Configure Cloud DNS to resolve *.googleapis.com to restricted.googleapis.com (199.36.153.4/30) across the VPC, and configure Serverless VPC Access connectors for the analytics tier.
Configure Cloud DNS response policies to map *.googleapis.com to restricted.googleapis.com (199.36.153.4/30) for VPC-wide egress, and deploy a Private Service Connect (PSC) endpoint for Google APIs with an allocated internal IP in the analytics subnet.
Enable standard Private Google Access on all subnets, and deploy an internal Application Load Balancer with a Private Service Connect backend pointing to all-apis for the analytics tier.
Configure Cloud DNS to resolve *.googleapis.com to private.googleapis.com (199.36.153.8/30) for the entire VPC, and create a Private Services Access (PSA) connection for the analytics subnet.
Configure Cloud DNS to resolve *.googleapis.com to restricted.googleapis.com (199.36.153.4/30) across the VPC, and configure Serverless VPC Access connectors for the analytics tier.
Configure Cloud DNS response policies to map *.googleapis.com to restricted.googleapis.com (199.36.153.4/30) for VPC-wide egress, and deploy a Private Service Connect (PSC) endpoint for Google APIs with an allocated internal IP in the analytics subnet.
This architecture combines Restricted Google Access via the restricted.googleapis.com domain with a Private Service Connect (PSC) endpoint for Google APIs. restricted.googleapis.com maps API domain names to a specific virtual IP range (199.36.153.4/30) that strictly permits communication only with Google services supported by VPC Service Controls (VPC-SC), while Private Service Connect projects Google API services directly into a consumer VPC network using a private RFC 1918 internal IP address.
*.googleapis.com and related domains to restricted.googleapis.com (199.36.153.4/30) ensures that compute workloads can only communicate with services verified to support VPC-SC perimeters. Any API call to a non-supported service (such as consumer web apps or unsupported APIs) is blocked at the network layer.restricted.googleapis.com VIP and PSC internal IP endpoints can be advertised across Cloud Interconnect or Cloud VPN to extend security postures to on-premises hosts.This dual approach applies the exact native mechanism intended for broad VPC-SC enforcement across the VPC (restricted.googleapis.com) while providing the dedicated analytics tier with private, subnet-bound addressing and firewall control via Private Service Connect.
Enable standard Private Google Access on all subnets, and deploy an internal Application Load Balancer with a Private Service Connect backend pointing to all-apis for the analytics tier.