Google
PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #139
You are a member of your company's security team. You have been asked to reduce your Linux bastion host external attack surface by removing all public IP addresses. Site Reliability Engineers (SREs)…
The correct answer is C. Implement Identity-Aware Proxy TCP forwarding for the bastion host. https://cloud.google.com/architecture/building-internet-connectivity-for-private- vms#configuring_iap_tunnels_for_interacting_with_instances
Submitted by jaden.t· Apr 18, 2026Configuring access within a cloud solution environment
Question
You are a member of your company's security team. You have been asked to reduce your Linux bastion host external attack surface by removing all public IP addresses. Site Reliability Engineers (SREs) require access to the bastion host from public locations so they can access the internal VPC while off-site. How should you enable this access?
Options
- AImplement Cloud VPN for the region where the bastion host lives.
- BImplement OS Login with 2-step verification for the bastion host.
- CImplement Identity-Aware Proxy TCP forwarding for the bastion host.
- DImplement Google Cloud Armor in front of the bastion host.
How the community answered
(21 responses)- A14% (3)
- B5% (1)
- C76% (16)
- D5% (1)
Explanation
https://cloud.google.com/architecture/building-internet-connectivity-for-private- vms#configuring_iap_tunnels_for_interacting_with_instances
Topics
#Identity-Aware Proxy (IAP)#Bastion Host#Secure Remote Access#Private Instance Access
Community Discussion
No community discussion yet for this question.