PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #170
PROFESSIONAL-CLOUD-SECURITY-ENGINEER Question #170: Real Exam Question with Answer & Explanation
Sign in or unlock PROFESSIONAL-CLOUD-SECURITY-ENGINEER to reveal the answer and full explanation for question #170. The question stem and answer options stay visible for context.
Question
Your organization's Google Cloud VMs are deployed via an instance template that configures them with a public IP address in order to host web services for external users. The VMs reside in a service project that is attached to a host (VPC) project containing one custom Shared VPC for the VMs. You have been asked to reduce the exposure of the VMs to the internet while continuing to service external users. You have already recreated the instance template without a public IP address configuration to launch the managed instance group (MIG). What should you do?
Options
- ADeploy a Cloud NAT Gateway in the service project for the MIG.
- BDeploy a Cloud NAT Gateway in the host (VPC) project for the MIG.
- CDeploy an external HTTP(S) load balancer in the service project with the MIG as a backend.
- DDeploy an external HTTP(S) load balancer in the host (VPC) project with the MIG as a backend.
Unlock PROFESSIONAL-CLOUD-SECURITY-ENGINEER to see the answer
You've previewed enough free PROFESSIONAL-CLOUD-SECURITY-ENGINEER questions. Unlock PROFESSIONAL-CLOUD-SECURITY-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.