Soru

Zorluk: ZorDesigning Infrastructure for Technical Requirements and High Availability

A global biotechnology enterprise is architecting a hybrid cloud solution on Google Cloud to ingest continuous high-throughput genomic sequencing datasets from its on-premises laboratories into Cloud Storage and BigQuery. The technical requirements demand a dedicated network throughput of at least 25 Gbps25\text{ Gbps} with a 99.99%99.99\% high availability SLA across physical connection failures, along with protection against data exfiltration by authorized internal identities to external cloud storage locations. Which architectural solution satisfies these technical availability and security requirements?

  1. Provision redundant 100 Gbps Dedicated Interconnect circuits across two distinct metropolitan locations configured with Global Dynamic Routing, and establish a VPC Service Controls perimeter around the project resources.Cevap
  2. B
    Provision multiple HA VPN tunnels with Equal-Cost Multi-Path (ECMP) routing across dual Cloud Routers, and apply granular IAM Storage Object Admin roles to enforce access control.
  3. C
    Provision redundant 100 Gbps Dedicated Interconnect circuits across two distinct metropolitan locations, and rely strictly on IAM roles and audit logging to restrict data movement to external storage endpoints.
  4. D
    Provision a single 100 Gbps Dedicated Interconnect circuit in one metropolitan location, and peer the ingress VPC with all analytical processing VPCs using VPC Network Peering for transitive hybrid routing.

Cevap

Provision redundant 100 Gbps Dedicated Interconnect circuits across two distinct metropolitan locations configured with Global Dynamic Routing, and establish a VPC Service Controls perimeter around the project resources.
The correct choice fulfills both high availability network performance and security exfiltration requirements. Deploying 100 Gbps Dedicated Interconnect across two distinct metropolitan areas fulfills Google's 99.99% uptime architecture guidelines for high bandwidth (>25 Gbps). Encapsulating the environment with VPC Service Controls creates a security perimeter that blocks data egress to external Google Cloud resources, preventing exfiltration even by authenticated identities.

Adım Adım Çözüm

1
Evaluate bandwidth and SLA connectivity requirements.
Sustained 25 Gbps25\text{ Gbps} throughput requires Dedicated Interconnect (as HA VPN is capped at 3 Gbps3\text{ Gbps} per tunnel). Achieving a 99.99%99.99\% SLA requires redundant connections across two different colocation facilities (metropolitan locations).
HA VPN cannot reliably support high continuous throughput scaling over 25 Gbps25\text{ Gbps}, and single-metro interconnects only offer a 99.9%99.9\% SLA.
2
Evaluate data exfiltration protection requirements.
VPC Service Controls must be implemented to create a security perimeter around GCP resources.
IAM permissions govern access rights but do not prevent authorized users or compromised service accounts from copying internal data into external GCP projects or buckets.
3
Synthesize the complete high availability and security architecture.
Selecting dual-metro Dedicated Interconnect combined with VPC Service Controls provides the required throughput, high availability SLA, and exfiltration boundary.
This combination addresses both technical infrastructure and security perimeter constraints without relying on non-transitive VPC peering topologies.

Anahtar Kavram

99.99% HA Dedicated Interconnect Architecture and VPC Service Controls Exfiltration Protection
Tahmini Süre:2m 30s
Bu soruyu puanla