Google Associate Cloud EngineerEnsuring successful operation of a cloud solutionHard

A team needs to ensure that all outbound internet traffic from their Compute Engine instances is routed through a single, central egress point for security inspection and policy enforcement. They want to avoid assigning external IP addresses directly to the instances. Which networking component should they configure?

  1. APrivate Google Access
  2. BVPC Service Controls
  3. CInternal Load Balancing
  4. DCloud NAT
Show answer & explanation

Correct answer: D. Cloud NAT

Cloud NAT (Network Address Translation) allows instances without external IP addresses to send outbound traffic to the internet through a shared set of NAT IP addresses, providing a central egress point for security inspection and policy enforcement.

Why the other options are wrong

  • A. Private Google Access allows instances without external IP addresses to reach Google APIs and services using internal IP addresses, but it does not provide general internet access.
  • B. VPC Service Controls help mitigate data exfiltration risks by creating security perimeters around services, but don't provide a central egress point for internet traffic from instances without external IPs.
  • C. Internal Load Balancing distributes internal traffic within a VPC network and is not used for outbound internet access.

Cloud NAT

A managed service that enables instances without external IP addresses to connect to the internet, providing a centralized egress point for outbound traffic.

  • Enables internet access for private VMs
  • Centralized egress point
  • No external IPs needed for instances

Memory trick: NAT is the gatekeeper for private VMs to talk to the net.

More Ensuring successful operation of a cloud solution questions