GCP ACE · Question 33 · Domain 4.1: Managing Compute Engine resources
You need to securely SSH into a Compute Engine instance that does NOT have an external public IP address. You want to use Identity-Aware Proxy (IAP) for TCP forwarding to achieve this.
Which TWO configurations are required to make this work? (Select TWO)
Answer options:
Assign an ephemeral public IP address to the instance.
Grant the user the 'IAP-secured Tunnel User' IAM role.
Create a firewall rule allowing ingress TCP traffic on port 22 from 0.0.0.0/0.
Create a firewall rule allowing ingress TCP traffic on port 22 from 35.235.240.0/20.
Configure a Cloud VPN connection to your local network.
50 questions · hints · full answers · grading