Allow SSH access from the internet to multiple Linux Compute Engine VMs that must not have public IPs, without adding per-VM SSH configuration. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure Cloud Identity-Aware Proxy for SSH and TCP resources.
Why this is the answer
Configuring Cloud Identity-Aware Proxy (IAP) for SSH and TCP resources allows you to securely access your Compute Engine VMs without assigning them public IP addresses. IAP acts as a centralized authorization gate, authenticating users and then forwarding their requests to your private instances. This method is scalable and eliminates the need for individual VM SSH configurations or bastion hosts. Configuring IAP for HTTPS resources is incorrect because SSH is not an HTTPS protocol. Storing SSH keypairs (public or private) as project-wide SSH keys would allow SSH access but does not address the requirement of VMs not having public IPs and still requires direct SSH connections, which IAP bypasses for enhanced security and simplified management.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed