nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #320

You work for an ecommerce company that stores sensitive customer data across multiple Google Cloud regions. The development team has built a new 3-tier application to process orders and must…

The correct answer is C. Create separate VPC networks for each tier. Use VPC peering between application tiers and. This approach ensures that each tier of the application is isolated within its own VPC, enhancing security. VPC peering allows necessary communication between tiers while maintaining isolation. Using Identity-Aware Proxy (IAP) for remote access ensures that only authorized…

Submitted by omar99· Apr 18, 2026Configuring network security

Question

You work for an ecommerce company that stores sensitive customer data across multiple Google Cloud regions. The development team has built a new 3-tier application to process orders and must integrate the application into the production environment. You must design the network architecture to ensure strong security boundaries and isolation for the new application, facilitate secure remote maintenance by authorized third-party vendors, and follow the principle of least privilege. What should you do?

Options

  • ACreate separate VPC networks for each tier. Use VPC peering between application tiers and
  • BCreate a single VPC network and create different subnets for each tier. Create a new Google
  • CCreate separate VPC networks for each tier. Use VPC peering between application tiers and
  • DCreate a single VPC network and create different subnets for each tier. Create a new Google

How the community answered

(55 responses)
  • A
    13% (7)
  • B
    5% (3)
  • C
    78% (43)
  • D
    4% (2)

Explanation

This approach ensures that each tier of the application is isolated within its own VPC, enhancing security. VPC peering allows necessary communication between tiers while maintaining isolation. Using Identity-Aware Proxy (IAP) for remote access ensures that only authorized vendors can access management resources, adhering to the principle of least privilege.

Topics

#Network Security#VPC Design#Network Segmentation#Least Privilege

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice