Soru

Zorluk: KolayConfiguring Network Topology and VPC Infrastructure

An enterprise engineering team is deploying a secure subnetwork for internal Compute Engine virtual machines that are configured without external IP addresses. The applications running on these instances require access to Google Cloud APIs (such as Cloud Storage) and also require outbound access to external third-party repositories for software updates without allowing inbound connections from the internet. Which TWO network topology configurations must be implemented in the Virtual Private Cloud (VPC) network to satisfy these connectivity requirements?

  1. Enable Private Google Access on the subnetwork where the virtual machines are deployed.Cevap
  2. Configure Cloud NAT associated with a Cloud Router on the VPC network for outbound internet connectivity.Cevap
  3. C
    Create a VPC Network Peering connection between the workload VPC network and Google API services network.
  4. D
    Attach Cloud Armor security policies directly to the subnetwork interface to permit outbound HTTP/HTTPS traffic.
  5. E
    Provision a Dedicated Interconnect connection to route all outbound internet update traffic through an on-premises network.

Cevap

The required configurations are enabling Private Google Access on the subnetwork and configuring Cloud NAT with a Cloud Router on the VPC network.
Enabling Private Google Access on the subnet provides private connectivity to Google Cloud APIs for instances without public IPs. Configuring Cloud NAT with Cloud Router allows these instances to establish outbound-only connections to third-party repositories on the internet for updates without exposing them to inbound internet traffic.

Adım Adım Çözüm

1
Identify the mechanism for internal instances to access Google Cloud services.
Enabling Private Google Access at the subnet level allows instances lacking external IP addresses to reach default Google API endpoints.
Internal VMs need a secure, managed route to access Google Cloud services like Cloud Storage without requiring public IP assignments.
2
Identify the mechanism for internal instances to send outbound traffic to external third-party endpoints.
Deploying Cloud NAT mapped to a Cloud Router provides network address translation for outbound internet connections.
Cloud NAT allows internal instances to initiate outbound connections for software updates while restricting inbound connections from external sources.

Anahtar Kavram

Configuring Private Google Access and Cloud NAT for internal VPC network topologies
Tahmini Süre:1m 0s
Bu soruyu puanla