🔥 3-day streak
Google Cloud Professional Cloud Network Engineer39 / 142
Question 39 of 142

Your security team requires that a set of Compute Engine instances in the 'restricted-vpc' custom-mode VPC have absolutely no direct path to the public internet, while still allowing them to reach Google APIs privately. Currently the VPC has the default 0.0.0.0/0 route pointing to the default internet gateway. The instances have no external IP addresses. What is the most effective way to guarantee these instances cannot egress to the internet through the default gateway while preserving private access to Google APIs?

Reviewed for accuracy · Report an issueNext question