nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #139

You are a member of your company's security team. You have been asked to reduce your Linux bastion host external attack surface by removing all public IP addresses. Site Reliability Engineers (SREs)…

The correct answer is C. Implement Identity-Aware Proxy TCP forwarding for the bastion host. https://cloud.google.com/architecture/building-internet-connectivity-for-private- vms#configuring_iap_tunnels_for_interacting_with_instances

Submitted by jaden.t· Apr 18, 2026Configuring access within a cloud solution environment

Question

You are a member of your company's security team. You have been asked to reduce your Linux bastion host external attack surface by removing all public IP addresses. Site Reliability Engineers (SREs) require access to the bastion host from public locations so they can access the internal VPC while off-site. How should you enable this access?

Options

  • AImplement Cloud VPN for the region where the bastion host lives.
  • BImplement OS Login with 2-step verification for the bastion host.
  • CImplement Identity-Aware Proxy TCP forwarding for the bastion host.
  • DImplement Google Cloud Armor in front of the bastion host.

How the community answered

(21 responses)
  • A
    14% (3)
  • B
    5% (1)
  • C
    76% (16)
  • D
    5% (1)

Explanation

https://cloud.google.com/architecture/building-internet-connectivity-for-private- vms#configuring_iap_tunnels_for_interacting_with_instances

Topics

#Identity-Aware Proxy (IAP)#Bastion Host#Secure Remote Access#Private Instance Access

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice