Your team needs to make sure that a Compute Engine instance does not have access to the internet or to any Google APIs or services. Which two settings must remain disabled to meet these requirements? (Choose two.)
B & C is the right answer.
Disabling the public IP can still route the traffic via NAT gateway if its configured in the VPC
VPC + NAT (Converts private IP to public ip) -> Internet and vise versa..
Whereas Disabling the IP forwarding will not route any traffic or doesn't act as a gatewy for any communication.
Private google access is enabled at Subnet level not at VM level. I am unsure why its not subnet. If you disable the route to internet- you cannot reach internet.
Correct Answer is AC
Option A : because per GCP documentation, “Prevent internet access to instances by setting them up with only a private IP address” meaning no public IPs.
Option C: because VM instances that only have internal IP addresses (no external IP addresses) can use Private Google Access. They can reach the external IP addresses of Google APIs and services.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
KILLMAD
Highly Voted 4 years, 8 months agorafaelc
4 years, 8 months agoZol
Highly Voted 4 years, 8 months agoCrypt0man27
Most Recent 2 months, 3 weeks agoPleeO
7 months agoelad17
1 year, 7 months agoTanu1912
1 year, 10 months agomj5677
1 year, 11 months agoDevXr
1 year, 11 months agoDevXr
1 year, 11 months agoMathDayMan
2 years agoMeyucho
2 years, 2 months agoGCP72
2 years, 3 months agomynk29
2 years, 9 months ago_01_
2 years, 11 months agomistryminded
3 years agoa_vi
3 years agojayk22
3 years ago