Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam Cloud Digital Leader All Questions

View all questions & answers for the Cloud Digital Leader exam

Exam Cloud Digital Leader topic 1 question 29 discussion

Actual exam question from Google's Cloud Digital Leader
Question #: 29
Topic #: 1
[All Cloud Digital Leader Questions]

Your organization runs all its workloads on Compute Engine virtual machine instances. Your organization has a security requirement: the virtual machines are not allowed to access the public internet. The workloads running on those virtual machines need to access BigQuery and Cloud Storage, using their publicly accessible interfaces, without violating the security requirement.
Which Google Cloud product or feature should your organization use?

  • A. Identity-Aware Proxy
  • B. Cloud NAT (network address translation)
  • C. VPC internal load balancers
  • D. Private Google Access
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
A_A_AB
Highly Voted 2 years, 10 months ago
Selected Answer: D
Agree with fpreli, the answer is D. According to the Google Documents >>> By default, when a Compute Engine VM lacks an external IP address assigned to its network interface, it can only send packets to other internal IP address destinations. You can allow these VMs to connect to the set of external IP addresses used by Google APIs and services by enabling Private Google Access on the subnet used by the VM's network interface. Besides, the security rules say no Internet access while NAt provite internet access. Google Private Access is like AWS VPC endpoint where you access GCP Public services without using Public Internet.
upvoted 31 times
...
harsh5kalsait
Most Recent 7 months, 2 weeks ago
Selected Answer: D
Agree with the answer is D. Virtual Private Google Access. Ref - https://cloud.google.com/vpc/docs/private-google-access
upvoted 2 times
...
Pearl81
10 months, 1 week ago
If it is a group of VMs with a specific IP range, then NAT works better. If there are VMs which doesn't fall with IP ranges, then PGA is best choice. Remember PGA can be enabled via subnet change through a button click. So it is easy simple and free of cost too.
upvoted 2 times
...
Surek
10 months, 3 weeks ago
D is the answer
upvoted 1 times
...
madcloud32
10 months, 3 weeks ago
Selected Answer: D
D is correct. NAT is option for securing Internet connection which is not ask. VM and other components are in cloud.
upvoted 2 times
...
sivakarthick16
11 months ago
Selected Answer: D
Private Google Access allows virtual machine instances in a VPC network to access Google Cloud services like BigQuery and Cloud Storage using internal IP addresses, without requiring public IP addresses or access to the public internet. By enabling Private Google Access, your organization can ensure that the workloads can securely access these services while adhering to the security requirement of not allowing access to the public internet.
upvoted 4 times
...
chai_gpt
1 year ago
Selected Answer: D
D is correct
upvoted 1 times
...
shares1998
1 year, 1 month ago
Selected Answer: D
D is right
upvoted 1 times
...
__rajan__
1 year, 1 month ago
Selected Answer: D
Private Google Access (PGA) allows you to access Google APIs and services from your on-premises network without exposing your workloads to the public internet. This is achieved by creating a private connection between your on-premises network and Google Cloud Platform (GCP).
upvoted 2 times
...
krischait
1 year, 1 month ago
Cloud NAT is a good option for organizations that need to allow their instances to access the internet, but want to protect them from unauthorized access. PGA is a good option for organizations that need to access Google APIs and services from their on-premises network without exposing their workloads to the public internet. Answer should be "D"
upvoted 3 times
...
mdsarfraz69
1 year, 1 month ago
Selected Answer: B
B is correct
upvoted 1 times
...
Lufly
1 year, 2 months ago
Selected Answer: D
why its not cloud nat? -> Cloud NAT: Cloud NAT is a service that allows you to access the public internet from your VMs. However, it does not allow you to control which services your VMs can access.
upvoted 4 times
...
prachisri
1 year, 3 months ago
Selected Answer: D
The document shared previously in this discussion is very useful to understand difference between PGA and NAT. This document clearly mentions "if we know the VMs in the subnet would never connect to internet except Google’s services, GPA is a better choice due to quick setup and better security." Hence, my answer is also D
upvoted 3 times
...
dnagasree
1 year, 3 months ago
Selected Answer: D
https://medium.com/@larry_nguyen/comparing-google-private-access-and-cloud-nat-cc43ddc9ce61 As per this article PGA is sufficient to access the Google services and NAT internally used PGA
upvoted 1 times
...
kmeena
1 year, 3 months ago
Answer D. Google documentation - https://cloud.google.com/vpc/docs/private-google-access "VM instances that only have internal IP addresses (no external IP addresses) can use Private Google Access. They can reach the external IP addresses of Google APIs and services" -> since they need to access BigQuery and Cloud Storage services
upvoted 3 times
...
MinaGohari
1 year, 3 months ago
Selected Answer: D
D is correct
upvoted 1 times
...
yadusaxena
1 year, 3 months ago
Correct answer is B. Dont ask me why but
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...