Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization implements a hub-and-spoke network architecture in Google Cloud. The architecture includes a centralized hub-vpc connected to an on-premises data center using Cloud Interconnect, and a separate spoke-vpc hosting application workloads. The two VPCs are interconnected using VPC Network Peering.
The security and network engineering teams have established the following requirements:
spoke-vpc through hub-vpc.hub-vpc must advertise the spoke-vpc address spaces to the on-premises Border Gateway Protocol (BGP) peers.hub-vpc must restrict incoming traffic based on the identity of workloads running in spoke-vpc without using IP CIDR blocks or non-functional cross-peering constructs.Which combination of routing configurations and firewall controls should the organization implement?
Configure custom IP range route advertisements on the hub-vpc Cloud Router, enable custom route export in hub-vpc and custom route import in spoke-vpc, and enforce ingress filtering using IAM-governed secure Resource Manager Tags as sources in network firewall policies.
Configure an Organization Policy with constraints/compute.restrictDedicatedInterconnectUsage to authorize spoke-vpc, enable default subnet route exchange, and apply hierarchical firewall rules using destination IP matching.
Assign dedicated IAM service accounts to spoke-vpc VM instances, reference those service accounts as source service accounts in hub-vpc firewall rules, and set dynamic routing mode to global in hub-vpc without custom advertisements.
Enable standard VPC dynamic route propagation, configure VPC Network Peering subnet route exchange, and apply traditional network tags to VM instances in spoke-vpc as source tags in hub-vpc VPC firewall rules.
Configure custom IP range route advertisements on the hub-vpc Cloud Router, enable custom route export in hub-vpc and custom route import in spoke-vpc, and enforce ingress filtering using IAM-governed secure Resource Manager Tags as sources in network firewall policies.
This solution pairs VPC Network Peering custom route exchange and Cloud Router custom route advertisements with IAM-governed Resource Manager Tags to satisfy cross-VPC hybrid routing constraints and strict boundary micro-segmentation.
hub-vpc Cloud Router allows on-premises BGP routers to learn routes to spoke-vpc subnets.hub-vpc peering configuration and custom route import on the spoke-vpc peering configuration permits on-premises dynamic routes learned by Cloud Router in hub-vpc to be imported into spoke-vpc.roles/resourcemanager.tagUser), preventing unauthorized VM tagging by local project administrators.Native custom route exchange and custom BGP advertisements eliminate latency overhead and maintenance burdens associated with Network Virtual Appliances (NVAs), while secure Resource Manager Tags provide the only native mechanism in Google Cloud network firewall policies to identify source workloads across VPC peering boundaries.
Configure an Organization Policy with constraints/compute.restrictDedicatedInterconnectUsage to authorize spoke-vpc, enable default subnet route exchange, and apply hierarchical firewall rules using destination IP matching.
Assign dedicated IAM service accounts to spoke-vpc VM instances, reference those service accounts as source service accounts in hub-vpc firewall rules, and set dynamic routing mode to global in hub-vpc without custom advertisements.
Enable standard VPC dynamic route propagation, configure VPC Network Peering subnet route exchange, and apply traditional network tags to VM instances in spoke-vpc as source tags in hub-vpc VPC firewall rules.