GCP ACE · Question 31 · Domain 4.1: Managing Compute Engine resources
You need to SSH into a Compute Engine instance that does not have an external public IP address. Your local workstation is not connected to the VPC via VPN or Interconnect.
What is the most secure and Google-recommended way to connect to this instance?
Answer options:
Assign an ephemeral external IP address to the instance temporarily.
Deploy a bastion host with a public IP address and SSH through it.
Use Identity-Aware Proxy (IAP) for TCP forwarding.
Configure Cloud NAT to allow inbound SSH connections.
50 questions · hints · full answers · grading