exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 316 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 316
Topic #: 1
[All Professional Cloud Security Engineer Questions]

You want to set up a secure, internal network within Google Cloud for database servers. The servers must not have any direct communication with the public internet. What should you do?

  • A. Assign a private IP address to each database server. Use a NAT gateway to provide internet connectivity to the database servers.
  • B. Assign a static public IP address to each database server. Use firewall rules to restrict external access.
  • C. Create a VPC with a private subnet. Assign a private IP address to each database server.
  • D. Assign both a private IP address and a public IP address to each database server.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
snti9999
1 week ago
Selected Answer: C
Q doesn’t ask for Internet
upvoted 1 times
...
YourFriendlyNeighborhoodSpider
1 month, 1 week ago
Selected Answer: C
If the question wanted you to allow INDIRECT access (like NAT), it should have been clearer about that. Instead, it's leaving room for pointless debate. In real-world best practices, databases should be in a private subnet with zero internet exposure unless absolutely required (e.g., for updates via a controlled egress path). So yeah, the question is badly worded, and people arguing for NAT are just nitpicking "direct" instead of focusing on security principles!!! SO ANSWER "C" MY DEARS!
upvoted 2 times
...
dlenehan
3 months, 3 weeks ago
Selected Answer: A
Allows indirect access to internet. Other options are more focused on direct access.
upvoted 2 times
...
Zek
4 months, 2 weeks ago
Selected Answer: A
I think A because it says "The servers must not have any direct communication with the public internet." Not direct bur suggest can be indirect access to internet
upvoted 3 times
...
dv1
6 months ago
A seems better to me, as the question says "db servers must not have DIRECT access to the internet".
upvoted 4 times
YourFriendlyNeighborhoodSpider
1 month, 1 week ago
if they meant to say that the VMs need "indirect" access to Internet - it would have been mentioned.
upvoted 1 times
...
MoAk
5 months ago
This is the way.
upvoted 1 times
JohnDohertyDoe
3 months, 3 weeks ago
But the question asks to create an internal network, not sure if they need internet access.
upvoted 2 times
...
...
...
abdelrahman89
6 months, 1 week ago
Selected Answer: C
Answer C
upvoted 3 times
YourFriendlyNeighborhoodSpider
1 month, 1 week ago
ABSOLUTELY RIGHT MY FRIEND
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago