🔥 3-day streak
Google Cloud Professional Cloud Network Engineer25 / 142
Question 25 of 142

A financial services company runs Compute Engine VMs with no external IP addresses in a private subnet. The security team requires two things for internet egress: (1) all outbound HTTP/HTTPS traffic must be restricted to an approved list of FQDNs (e.g., only *.partnerbank.com and api.provider.net), and (2) any non-HTTP(S) egress that is still permitted must be source-NATed through a predictable set of static IP addresses so partners can allowlist them. What should you deploy to meet BOTH requirements with the least operational overhead?

Reviewed for accuracy · Report an issueNext question