🔥 3-day streak
Google Cloud Professional Cloud Network Engineer40 / 142
Question 40 of 142

Your company runs a custom-mode VPC with many Compute Engine instances in the subnet 10.20.0.0/16. Most instances must send all internet-bound traffic through a self-managed NAT/firewall appliance (a VM with IP 10.20.1.10) for inspection. However, a small group of instances tagged 'direct-egress' must instead use the default internet gateway route for maximum throughput and bypass inspection. Both route types point to 0.0.0.0/0. How should you configure routing so that only the tagged instances bypass the appliance?

Reviewed for accuracy · Report an issueNext question