Professional Cloud Security EngineerConfiguring network securityHard

A company is designing a new microservices architecture on Google Cloud. They have several internal services that should only be accessible by other authorized internal services within the same VPC, without exposing them to the public internet or requiring complex firewall rules for every service-to-service communication. They also want to consume managed Google services (e.g., Cloud SQL, Cloud Storage) privately from their VPC. Which Google Cloud networking feature enables this private connectivity pattern for both internal and managed services?

  1. APrivate Service Connect and Private Google Access
  2. BVPC Service Controls and Cloud DNS
  3. CShared VPC and Cloud VPN
  4. DCloud Interconnect and VPC Firewall Rules
Show answer & explanation

Correct answer: A. Private Service Connect and Private Google Access

Private Service Connect allows internal services to expose themselves privately to other VPCs, and for VPCs to consume managed services privately. Private Google Access enables VMs without external IP addresses to access Google APIs and services privately, fulfilling all requirements for internal and managed service private connectivity.

Why the other options are wrong

  • B. VPC Service Controls protect against data exfiltration, and Cloud DNS manages name resolution; these are not for private service exposure or consumption.
  • C. Shared VPC allows multiple projects to use a common VPC, and Cloud VPN connects to on-premises, neither addresses internal service-to-service private exposure or managed service consumption without external IPs.
  • D. Cloud Interconnect connects on-premises to GCP, and VPC Firewall Rules control traffic, but neither directly provides the private exposure/consumption pattern for internal and managed services within VPCs.

Private Service Connect & Private Google Access

Private Service Connect allows private consumption of services across VPCs or from Google-managed services. Private Google Access enables VMs without external IPs to privately access Google APIs and services.

  • PSC for internal service exposure/consumption
  • PSC for managed service consumption
  • PGA for VMs to access Google APIs privately without external IPs

Memory trick: Private connections keep services talking securely without showing their faces to the world.

More Configuring network security questions