Google Associate Cloud EngineerEnsuring successful operation of a cloud solutionHard
A team needs to ensure that all outbound internet traffic from their Compute Engine instances is routed through a single, central egress point for security inspection and policy enforcement. They want to avoid assigning external IP addresses directly to the instances. Which networking component should they configure?
- APrivate Google Access
- BVPC Service Controls
- CInternal Load Balancing
- DCloud NAT
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud NAT
Cloud NAT (Network Address Translation) allows instances without external IP addresses to send outbound traffic to the internet through a shared set of NAT IP addresses, providing a central egress point for security inspection and policy enforcement.
Why the other options are wrong
- A. Private Google Access allows instances without external IP addresses to reach Google APIs and services using internal IP addresses, but it does not provide general internet access.
- B. VPC Service Controls help mitigate data exfiltration risks by creating security perimeters around services, but don't provide a central egress point for internet traffic from instances without external IPs.
- C. Internal Load Balancing distributes internal traffic within a VPC network and is not used for outbound internet access.
Cloud NAT
A managed service that enables instances without external IP addresses to connect to the internet, providing a centralized egress point for outbound traffic.
- Enables internet access for private VMs
- Centralized egress point
- No external IPs needed for instances
Memory trick: NAT is the gatekeeper for private VMs to talk to the net.