nerdexam
GoogleGoogle

ASSOCIATE-CLOUD-ENGINEER · Question #408

ASSOCIATE-CLOUD-ENGINEER Question #408: Real Exam Question with Answer & Explanation

Sign in or unlock ASSOCIATE-CLOUD-ENGINEER to reveal the answer and full explanation for question #408. The question stem and answer options stay visible for context.

Submitted by packet_pusher· Mar 30, 2026

Question

You are deploying a large, multi-tiered application with more than 1,000 IP addresses in a Google Cloud project that needs to be securely isolated. The application includes the: 1. web tier with frontend servers for public traffic, 2. application tier with servers running core application logic that only need access from the web tier, and 3. database tier with database servers that only need access from the application tier. You want to minimize cost, complexity, and administrative overhead in the network architecture. What should you do?

Options

  • ACreate a /24 Shared VPC with separate subnets for each tier. Use firewall rules that reference
  • BCreate one custom mode /16 VPC with three subnets. Place each tier in its own subnet and use
  • CDeploy each tier into a separate custom mode /16 VPC. Use VPC Network Peering to securely
  • DDeploy each tier in a /24 VPC by using network tags to identify instances. Implement firewall rules

Unlock ASSOCIATE-CLOUD-ENGINEER to see the answer

You've previewed enough free ASSOCIATE-CLOUD-ENGINEER questions. Unlock ASSOCIATE-CLOUD-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full ASSOCIATE-CLOUD-ENGINEER PracticeBrowse All ASSOCIATE-CLOUD-ENGINEER Questions