GCP ACE · Question 33 · Domain 4.1: Managing Compute Engine resources
You have a Compute Engine instance that does NOT have an external public IP address. You need to connect to this instance via SSH from your local workstation over the internet securely.
Which TWO actions must you take to enable this using Identity-Aware Proxy (IAP)? (Select TWO)
Answer options:
Assign a temporary external IP address to the instance.
Ensure your user account has the 'IAP-secured Tunnel User' IAM role.
Create an ingress firewall rule allowing TCP port 22 from the IAP IP range (35.235.240.0/20).
Configure Cloud VPN between your workstation and the VPC.
Install the IAP agent on the guest OS of the VM.
50 questions · hints · full answers · grading