☎  076 959 6407✉  support@quizcrazepro.co.za
Learn. Practice. Build your future.
BlogHelpContact
G

Google Professional Cloud Security Engineer Actual Exam Questions

318 Questions120 Minutes70% Passing Score▣ Updated: Sep 2026

Question 204 of 318

Choose 2
Your DevOps team uses Packer to build Compute Engine images by using this process:
1. Create an ephemeral Compute Engine VM.
2. Copy a binary from a Cloud Storage bucket to the VM's file system.
3. Update the VM's package manager.
4. Install external packages from the internet onto the VM.
Your security team just enabled the organizational policy, constraints/ compute.vmExternalIpAccess, to restrict the usage of public IP Addresses on VMs. In response, your DevOps team updated their scripts to remove public IP addresses on the Compute Engine VMs; however, the build pipeline is failing due to connectivity issues.
What should you do? (Choose two.)
AProvision an HTTP load balancer with the VM in an unmanaged instance group to allow inbound connections from the internet to your VM.
BProvision a Cloud NAT instance in the same VPC and region as the Compute Engine VM.
CEnable Private Google Access on the subnet that the Compute Engine VM is deployed within.
DUpdate the VPC routes to allow traffic to and from the internet.
EProvision a Cloud VPN tunnel in the same VPC and region as the Compute Engine VM.
Correct Answer: B, C

Provision a Cloud NAT instance in the same VPC and region as the Compute Engine VM.

Explanation

The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of Google certification topics.

About this practice exam

Review 318 Google questions with answers and explanations. Use the navigation to move through the exam at your own pace.