Google Associate Cloud EngineerPlanning and configuring a cloud solutionMedium
A company is planning to deploy a new application that will process sensitive customer data. They need to ensure that the application's network traffic cannot be accessed by other projects or organizations within Google Cloud, even if they share the same physical infrastructure. What networking construct should be used to provide this isolation?
- APublic IP addresses
- BShared VPC
- CVirtual Private Cloud (VPC) network
- DVPC Network Peering
Show answer & explanationAnswer & explanation
Correct answer: C. Virtual Private Cloud (VPC) network
A Virtual Private Cloud (VPC) network provides a logically isolated network for your Google Cloud resources. Even though Google Cloud infrastructure is shared, your VPC network is private and traffic within it cannot be accessed by other tenants, ensuring the required isolation for sensitive data.
Why the other options are wrong
- A. Public IP addresses expose resources to the internet, directly contradicting the need for isolation and privacy.
- B. Shared VPC allows multiple projects to use a common VPC network, which is about sharing, not isolation between distinct projects/organizations.
- D. VPC Network Peering connects two separate VPC networks, but the fundamental isolation is provided by each VPC network itself.
Virtual Private Cloud (VPC) Network
A global, logically isolated network on Google Cloud that provides networking functionality for Google Cloud resources. It enables resources in different regions to communicate and provides a private IP space.
- Logically isolated network
- Global scope (can span regions)
- Provides private IP addresses for resources
- Enables secure and private communication between resources
- Acts as a foundation for network security policies
Memory trick: Network Isolation: Your cloud 'home' needs a strong 'fence' around it!