Question 120 of 318
Single answerYour organization acquired a new workload. The Web and Application (App) servers will be running on Compute Engine in a newly created custom VPC. You are responsible for configuring a secure network communication solution that meets the following requirements:
? Only allows communication between the Web and App tiers.
? Enforces consistent network security when autoscaling the Web and App tiers.
? Prevents Compute Engine Instance Admins from altering network traffic.
What should you do?
? Only allows communication between the Web and App tiers.
? Enforces consistent network security when autoscaling the Web and App tiers.
? Prevents Compute Engine Instance Admins from altering network traffic.
What should you do?
A1. Configure all running Web and App servers with respective network tags.
2. Create an allow VPC firewall rule that specifies the target/source with respective network tags.
2. Create an allow VPC firewall rule that specifies the target/source with respective network tags.
B1. Configure all running Web and App servers with respective service accounts.
2. Create an allow VPC firewall rule that specifies the target/source with respective service accounts.
2. Create an allow VPC firewall rule that specifies the target/source with respective service accounts.
C1. Re-deploy the Web and App servers with instance templates configured with respective network tags.
2. Create an allow VPC firewall rule that specifies the target/source with respective network tags.
2. Create an allow VPC firewall rule that specifies the target/source with respective network tags.
✓D1. Re-deploy the Web and App servers with instance templates configured with respective service accounts.
2. Create an allow VPC firewall rule that specifies the target/source with respective service accounts.
2. Create an allow VPC firewall rule that specifies the target/source with respective service accounts.
✓
Correct Answer: D
1. Re-deploy the Web and App servers with instance templates configured with respective service accounts.<br> 2. Create an allow VPC firewall rule that specifies the target/source with respective service accounts.
▥
Explanation
The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of Google certification topics.