ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 143 - Professional Cloud Security Engineer discussion

Report
Export

Your organization hosts a financial services application running on Compute Engine instances for a third-party company. The third-party company's servers that will consume the application also run on Compute Engine in a separate Google Cloud organization. You need to configure a secure network connection between the Compute Engine instances. You have the following requirements:

The network connection must be encrypted.

The communication between servers must be over private IP addresses.

What should you do?

A.
Configure a Cloud VPN connection between your organization's VPC network and the third party's that is controlled by VPC firewall rules.
Answers
A.
Configure a Cloud VPN connection between your organization's VPC network and the third party's that is controlled by VPC firewall rules.
B.
Configure a VPC peering connection between your organization's VPC network and the third party's that is controlled by VPC firewall rules.
Answers
B.
Configure a VPC peering connection between your organization's VPC network and the third party's that is controlled by VPC firewall rules.
C.
Configure a VPC Service Controls perimeter around your Compute Engine instances, and provide access to the third party via an access level.
Answers
C.
Configure a VPC Service Controls perimeter around your Compute Engine instances, and provide access to the third party via an access level.
D.
Configure an Apigee proxy that exposes your Compute Engine-hosted application as an API, and is encrypted with TLS which allows access only to the third party.
Answers
D.
Configure an Apigee proxy that exposes your Compute Engine-hosted application as an API, and is encrypted with TLS which allows access only to the third party.
Suggested answer: B

Explanation:

Google encrypts and authenticates data in transit at one or more network layers when data moves outside physical boundaries not controlled by Google or on behalf of Google. All VM-to-VM traffic within a VPC network and peered VPC networks is encrypted. https://cloud.google.com/docs/security/encryption-in-transit#cio-level_summary

asked 18/09/2024
Alvin Thomas
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first