Professional Cloud Security EngineerConfiguring network securityHard

A global company is setting up a new Google Cloud environment. They have multiple VPC networks in different regions and need to allow secure, private communication between specific services in these different VPCs without exposing any traffic to the public internet. They want to avoid full VPC network peering due to overlapping IP ranges and the complexity of managing shared routing tables. Which Google Cloud networking feature should they use?

  1. AVPC Network Peering
  2. BPrivate Service Connect (Endpoints)
  3. CShared VPC
  4. DCloud VPN
Show answer & explanation

Correct answer: B. Private Service Connect (Endpoints)

Private Service Connect endpoints allow consumers to privately access services published by other VPCs (even with overlapping IP ranges) without using VPC Network Peering and without traversing the public internet. This provides granular, private connectivity between specific services.

Why the other options are wrong

  • A. VPC Network Peering requires non-overlapping IP ranges and connects entire VPCs, which is not desired due to complexity and IP range issues.
  • C. Shared VPC is for sharing a host VPC network across multiple projects, not for private service-to-service communication between independent VPCs with potential IP overlaps.
  • D. Cloud VPN uses the public internet for encrypted tunnels, which violates the 'without exposing any traffic to the public internet' requirement for this internal scenario.

Private Service Connect (Endpoints)

Private Service Connect (PSC) allows private access to services deployed in other VPC networks (producer VPCs) from a consumer VPC, using internal IP addresses and avoiding IP range conflicts.

  • Enables private service consumption across different VPCs/projects.
  • Supports overlapping IP addresses between consumer and producer VPCs.
  • Does not require VPC Network Peering and avoids public internet.

Memory trick: PSC endpoints are private doors between specific services in different VPCs.

More Configuring network security questions