Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise is securing its Google Cloud environment to minimize perimeter attack surfaces and prevent unintended internet exposure. The security architect establishes the following requirements:
Which combination of architectural controls and services should the security architect deploy?
Enforce the Disable VPC External IPv6 usage constraint, create an internal Application Load Balancer with an INTERNET_IP_PORT backend, and use VPC Network Peering with Exchange subnet routes with public IP enabled for external communication.
Enforce the Define allowed external IPs for VM instances organization policy constraint to Deny All, deploy Cloud NAT gateways in the VPC, configure Identity-Aware Proxy (IAP) for TCP forwarding with a firewall rule permitting 35.235.240.0/20 for ports 22 and 3389, and use external Application Load Balancers with reserved external IP addresses.
Enforce the Skip default network creation constraint to True, configure Cloud NAT to handle both inbound and outbound traffic, permit 0.0.0.0/0 on firewall ports 22 and 3389, and use Cloud DNS routing policies for external web ingestion.
Enforce the Restrict Protocol Forwarding Based on type of IP Address constraint set to IS:EXTERNAL, deploy Internet NEGs pointing to private RFC 1918 VM addresses, and allow health check ranges 35.191.0.0/16 and 130.211.0.0/22 for SSH management.
Enforce the Disable VPC External IPv6 usage constraint, create an internal Application Load Balancer with an INTERNET_IP_PORT backend, and use VPC Network Peering with Exchange subnet routes with public IP enabled for external communication.
Enforce the Define allowed external IPs for VM instances organization policy constraint to Deny All, deploy Cloud NAT gateways in the VPC, configure Identity-Aware Proxy (IAP) for TCP forwarding with a firewall rule permitting 35.235.240.0/20 for ports 22 and 3389, and use external Application Load Balancers with reserved external IP addresses.
This architecture combines preventive organizational governance, edge translation, zero-trust administrative access, and managed reverse-proxy ingress to isolate virtual machines entirely within private IP address spaces while retaining full outbound capability, secure management, and public service delivery.
constraints/compute.vmExternalIpAccess) organization policy constraint with a policy value of Deny All replaces default behaviors and blocks any Compute Engine instance in the organization from acquiring public external IP addresses.35.235.240.0/20 allows authenticated, authorized administrators to access VMs without assigning public IPs or running dedicated bastion hosts.This pattern aligns with defense-in-depth and zero-trust principles by ensuring that compute resources never maintain direct public IP bindings while cleanly separating inbound reverse-proxy edge routing, outbound egress translation, and IAM-gated administrative access.
Enforce the Skip default network creation constraint to True, configure Cloud NAT to handle both inbound and outbound traffic, permit 0.0.0.0/0 on firewall ports 22 and 3389, and use Cloud DNS routing policies for external web ingestion.
Enforce the Restrict Protocol Forwarding Based on type of IP Address constraint set to IS:EXTERNAL, deploy Internet NEGs pointing to private RFC 1918 VM addresses, and allow health check ranges 35.191.0.0/16 and 130.211.0.0/22 for SSH management.