🔥 3-day streak
Google Cloud Professional Cloud Network Engineer124 / 142
Question 124 of 142

A financial services company runs application VMs in a VPC with no external IP addresses. Compliance requires that all outbound HTTPS traffic to the internet be inspected and restricted so that VMs can only reach an approved allowlist of external hostnames (for example, *.partner-bank.com and api.marketdata.io). The security team wants a fully managed Google Cloud service that enforces these URL/hostname policies with TLS inspection, rather than deploying and maintaining their own proxy fleet. Which approach should you implement?

Reviewed for accuracy · Report an issueNext question