🔥 3-day streak
Google Cloud Professional Cloud Network Engineer125 / 142
Question 125 of 142
A financial services company runs application VMs in a private subnet (no external IPs) that must reach a specific list of approved SaaS HTTPS endpoints on the internet. Security requires that egress be filtered by fully-qualified domain name (not just IP), that TLS sessions be intercepted and inspected against the allowlist, and that all egress decisions be centrally logged. The team already uses Cloud NAT for other workloads. Which approach meets these requirements?
Reviewed for accuracy · Report an issueNext question