GCP PCA · Question 23 · Domain 2: Managing and Provisioning a Solution Infrastructure
You are designing a multi-tier application in Google Cloud. The web tier is in a public subnet, and the database tier is in a private subnet with no external IP addresses. The database instances need to download software updates from the internet. How should you configure this securely?
Answer options:
Assign ephemeral external IP addresses to the database instances.
Configure Cloud NAT for the private subnet.
Enable Private Google Access on the subnet.
Set up a proxy server in the public subnet and route database traffic through it.
50 questions · hints · full answers · grading