Professional Cloud Security EngineerConfiguring network securityMedium
A financial institution is migrating its on-premises data center to Google Cloud. They require a high-bandwidth, low-latency, and highly available private connection between their on-premises network and their Google Cloud VPC, bypassing the public internet entirely. They also need to manage multiple VLAN attachments for different environments (production, staging, development) over this connection. Which Google Cloud service combination should they use?
- ACloud DNS and Private Service Connect
- BCloud CDN and Cloud Load Balancing
- CCloud Interconnect (Dedicated) and VLAN attachments
- DCloud VPN and Shared VPC
Show answer & explanationAnswer & explanation
Correct answer: C. Cloud Interconnect (Dedicated) and VLAN attachments
Dedicated Interconnect provides a direct physical connection with high bandwidth and low latency, bypassing the public internet. VLAN attachments allow for segmenting traffic for different environments over that single physical connection, meeting all requirements.
Why the other options are wrong
- A. Cloud DNS manages domain resolution, and Private Service Connect is for private consumption of services, not for on-premises to VPC private connectivity.
- B. Cloud CDN and Cloud Load Balancing are for content delivery and traffic distribution, not private network connectivity.
- D. Cloud VPN uses the public internet and typically offers lower bandwidth than required for this scenario.
Cloud Interconnect (Dedicated)
Dedicated Interconnect provides direct physical connections between an on-premises network and Google Cloud, offering high bandwidth and low latency.
- Direct physical connection
- Bypasses public internet
- Supports VLAN attachments for segmentation
Memory trick: Private connections are like a superhighway for data, not a bumpy backroad.