Professional Cloud ArchitectDesign and plan a cloud solution architectureHard
A global financial institution is planning to migrate its highly regulated, mission-critical applications to Google Cloud. These applications process sensitive customer data and require strict isolation and control over the underlying infrastructure. The institution's security policies mandate that all network traffic, including communication between virtual machines within the same Virtual Private Cloud (VPC), must be inspected by a third-party firewall appliance. Which Google Cloud networking feature should you recommend to meet this requirement while maintaining high performance and scalability?
- AVPC Flow Logs
- BShared VPC with Google Cloud's Network Connectivity Center and third-party NVA integration
- CVPC Network Peering with custom route advertisements
- DVPC Firewall Rules with Service Accounts
Show answer & explanationAnswer & explanation
Correct answer: B. Shared VPC with Google Cloud's Network Connectivity Center and third-party NVA integration
For strict, centralized inspection of all traffic, including intra-VPC, by a third-party Network Virtual Appliance (NVA), Shared VPC combined with Network Connectivity Center and the NVA integration is the most robust solution. This allows routing all relevant traffic through the NVA for inspection.
Why the other options are wrong
- A. VPC Flow Logs only provide logging of network flows, not active inspection or enforcement.
- C. VPC Network Peering connects two VPCs but doesn't inherently force traffic through a centralized third-party inspection point for all traffic within a single or multiple VPCs.
- D. VPC Firewall Rules are Google Cloud's native firewall and cannot integrate a third-party appliance for inspection of all traffic types, especially intra-VPC.
Network Virtual Appliance (NVA) Integration
Integrating third-party network security appliances, such as firewalls or intrusion detection systems, into a Google Cloud VPC to provide advanced traffic inspection and policy enforcement.
- Enables specialized security features not native to GCP firewalls.
- Often used in highly regulated environments for deep packet inspection.
- Requires careful routing and network design to direct traffic through the NVA.
Memory trick: Secure networks funnel traffic through a central checkpoint.