Professional Cloud ArchitectManage and provision solution infrastructureHard

A security-conscious organization needs to ensure that all network traffic from their Compute Engine instances to the internet passes through a centralized set of security appliances (e.g., firewalls, intrusion detection systems) hosted in a dedicated VPC network. They require a solution that forces all outbound traffic through these appliances without relying on proxy configurations on each instance. Which networking solution should they implement?

  1. AShared VPC with custom firewall rules
  2. BVPC Network Peering with a custom route for default internet gateway
  3. CCloud NAT with egress rules
  4. DCentralized egress with custom static routes and Next Hop VPN tunnel
Show answer & explanation

Correct answer: D. Centralized egress with custom static routes and Next Hop VPN tunnel

Centralized egress with custom static routes and a Next Hop VPN tunnel (or internal load balancer to the security appliances) forces all outbound internet traffic through the specified appliances in a dedicated network. This ensures all traffic is inspected without modifying each instance's configuration.

Why the other options are wrong

  • A. Shared VPC facilitates network resource sharing but does not inherently force all egress traffic through centralized security appliances without specific routing configurations to achieve that goal.
  • B. VPC Network Peering connects VPCs, but merely having peering and a custom route for 'default internet gateway' isn't specific enough to describe how traffic is *forced* through appliances. The next hop for that route is critical.
  • C. Cloud NAT allows private instances to access the internet but does not provide a mechanism to force all traffic through a specific set of security appliances for inspection. It simply performs network address translation.

Centralized Egress with Custom Routes

A networking pattern where all outbound internet traffic from multiple VPC networks is routed through a single, dedicated VPC network that hosts security appliances (e.g., firewalls, IDSs). This is achieved using custom static routes with a next hop pointing to the security appliances (often via an Internal Load Balancer or VPN tunnel).

  • Forces all outbound traffic through centralized security controls
  • Uses custom static routes (e.g., 0.0.0.0/0) to redirect traffic
  • Next hop typically points to an Internal Load Balancer or VPN tunnel in a security VPC
  • Ensures consistent security policy application
  • Simplifies management by centralizing security infrastructure

Memory trick: Route traffic to the security hub before it hits the internet.

More Manage and provision solution infrastructure questions