Professional Data EngineerBuilding and operationalizing data processing systemsMedium

A financial institution processes sensitive customer transaction data daily. The data is generated on-premises and needs to be ingested into Google Cloud for processing and analysis in BigQuery. Due to strict security and compliance requirements, the data cannot traverse the public internet, and a direct, private, and highly available connection is mandated. Which Google Cloud networking solution should be used to securely ingest this data?

  1. ACloud VPN (HA VPN)
  2. BVPN over public internet
  3. CCloud Interconnect (Dedicated)
  4. DDirect Peering
Show answer & explanation

Correct answer: C. Cloud Interconnect (Dedicated)

Cloud Interconnect (Dedicated) provides a direct, private physical connection between an on-premises network and Google's network, ensuring data does not traverse the public internet and offering high availability.

Why the other options are wrong

  • A. Cloud VPN (HA VPN) uses IPsec VPN tunnels over the public internet, which is not allowed.
  • B. VPN over public internet still uses the public internet, violating the security requirement.
  • D. Direct Peering is for exchanging traffic directly with Google, but it's not typically used for private connectivity to a customer's VPC network.

Cloud Interconnect (Dedicated)

Cloud Interconnect (Dedicated) provides a direct physical connection between an on-premises data center and Google's network, bypassing the public internet.

  • Private, dedicated connection.
  • High bandwidth and low latency.
  • Enhanced security and compliance.
  • Requires physical presence at a Google colocation facility.

Memory trick: Private paths for precious packets, bypassing the public's prying eyes.

More Building and operationalizing data processing systems questions