Question 56

You want to configure a NAT to perform address translation between your on-premises network blocks and GCP.
Which NAT solution should you use?
  • Question 57

    You have an application running on Compute Engine that uses BigQuery to generate some results that are stored in Cloud Storage. You want to ensure that none of the application instances have external IP addresses.
    Which two methods can you use to accomplish this? (Choose two.)
  • Question 58

    Your company is working with a partner to provide a solution for a customer. Both your company and the partner organization are using GCP. There are applications in the partner's network that need access to some resources in your company's VPC. There is no CIDR overlap between the VPCs.
    Which two solutions can you implement to achieve the desired results without compromising the security?
    (Choose two.)
  • Question 59

    You are migrating a three-tier application architecture from on-premises to Google Cloud. As a first step in the migration, you want to create a new Virtual Private Cloud (VPC) with an external HTTP(S) load balancer. This load balancer will forward traffic back to the on-premises compute resources that run the presentation tier. You need to stop malicious traffic from entering your VPC and consuming resources at the edge, so you must configure this policy to filter IP addresses and stop cross-site scripting (XSS) attacks. What should you do?
  • Question 60

    Refer to the exhibit.
    You have the following firewall ruleset applied to all instances in your Virtual Private Cloud (VPC):

    You need to update the firewall rule to add the following rule to the ruleset:

    You are using a new user account. You must assign the appropriate identity and Access Management (IAM) user roles to this new user account before updating the firewall rule. The new user account must be able to apply the update and view firewall logs. What should you do?