ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 119 - Professional Cloud Security Engineer discussion

Report
Export

You are a member of your company's security team. You have been asked to reduce your Linux bastion host external attack surface by removing all public IP addresses. Site Reliability Engineers (SREs) require access to the bastion host from public locations so they can access the internal VPC while off-site. How should you enable this access?

A.
Implement Cloud VPN for the region where the bastion host lives.
Answers
A.
Implement Cloud VPN for the region where the bastion host lives.
B.
Implement OS Login with 2-step verification for the bastion host.
Answers
B.
Implement OS Login with 2-step verification for the bastion host.
C.
Implement Identity-Aware Proxy TCP forwarding for the bastion host.
Answers
C.
Implement Identity-Aware Proxy TCP forwarding for the bastion host.
D.
Implement Google Cloud Armor in front of the bastion host.
Answers
D.
Implement Google Cloud Armor in front of the bastion host.
Suggested answer: C

Explanation:

https://cloud.google.com/architecture/building-internet-connectivity-for-private-vms#configuring_iap_tunnels_for_interacting_with_instances

asked 18/09/2024
Rob Kennis
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first