Google
PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #107
You need to enable Private Google Access for use by some subnets within your Virtual Private Cloud (VPC). Your security team set up the VPC to send all internet-bound traffic back to the on- premises
The correct answer is A. Create a private DNS zone with a CNAME record for *.googleapis.com to. Choose restricted.googleapis.com when you only need access to Google APIs and services that are supported by VPC Service Controls.
Submitted by eva_at· Apr 18, 2026Configuring network services
Question
You need to enable Private Google Access for use by some subnets within your Virtual Private Cloud (VPC). Your security team set up the VPC to send all internet-bound traffic back to the on- premises data center for inspection before egressing to the internet, and is also implementing VPC Service Controls in the environment for API-level security control. You have already enabled the subnets for Private Google Access. What configuration changes should you make to enable Private Google Access while adhering to your security team's requirements?
Options
- ACreate a private DNS zone with a CNAME record for *.googleapis.com to
- BCreate a private DNS zone with a CNAME record for *.googleapis.com to
- CCreate a private DNS zone with a CNAME record for *.googleapis.com to private.googleapis.com,
- DCreate a private DNS zone with a CNAME record for *.googleapis.com to private.googleapis.com,
How the community answered
(34 responses)- A79% (27)
- B6% (2)
- C3% (1)
- D12% (4)
Explanation
Choose restricted.googleapis.com when you only need access to Google APIs and services that are supported by VPC Service Controls.
Topics
#Private Google Access#VPC Service Controls#Cloud DNS#API Connectivity
Community Discussion
No community discussion yet for this question.