Your organization has decided to restrict the use of external IP addresses on instances to only approved instances. You want to enforce this requirement across all of your Virtual Private Clouds (VPCs). What should you do?
A.
Remove the default route on all VPCs. Move all approved instances into a new subnet that has a default route to an internet gateway.
B.
Create a new VPC in custom mode. Create a new subnet for the approved instances, and set a default route to the internet gateway on this new subnet.
C.
Implement a Cloud NAT solution to remove the need for external IP addresses entirely.
D.
Set an Organization Policy with a constraint on constraints/compute.vmExternalIpAccess. List the approved instances in the allowedValues list.
Ans - D, https://cloud.google.com/compute/docs/ip-addresses/reserve-static-external-ip-address#disableexternalip
you might want to restrict external IP address so that only specific VM instances can use them. This option can help to prevent data exfiltration or maintain network isolation. Using an Organization Policy, you can restrict external IP addresses to specific VM instances with constraints to control use of external IP addresses for your VM instances within an organization or a project.
"You cannot apply the constraint retroactively. All VMs that have external IP addresses before you enable the policy retain their external IP addresses."
https://cloud.google.com/compute/docs/ip-addresses/reserve-static-external-ip-address#disableexternalip
It shouldn't be option D then
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
victory108
Highly Voted 3 years, 2 months agoAnilKr
Highly Voted 3 years, 1 month agoplumbig11
Most Recent 2 months, 4 weeks agojames2033
4 months agoodacir
7 months, 1 week agobeehive
1 year, 9 months agorascalbrick
1 year, 9 months agomegumin
1 year, 10 months agoAzureDP900
1 year, 11 months ago2M
2 years agoACE_ASPIRE
2 years, 1 month agoSur_Nikki
1 year, 4 months agoAzureDP900
2 years, 2 months agoJoeyCASD
2 years, 4 months agoss909098
2 years, 6 months ago[Removed]
2 years, 7 months agotechnodev
2 years, 8 months agoharoldbenites
2 years, 9 months ago