Internal company app on a single Compute Engine VM must allow Google Workspace users to authenticate from anywhere. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Add an HTTP(S) load balancer in front of the instance, and set up Identity-Aware Proxy (IAP). Configure the IAP settings to allow your company domain to access the website..
Why this is the answer
The correct option uses Identity-Aware Proxy (IAP) with an HTTP(S) load balancer. IAP allows you to control access to your application based on user identity, integrating directly with Google Workspace for authentication. This provides secure access from anywhere without exposing the VM directly to the internet. Adding a public IP and restricting by firewall rules to a company proxy only works if all users are always behind that proxy, which isn't guaranteed when users are "anywhere." Setting up a VPN is complex and typically used for network-level connectivity, not application-level authentication for individual users from various locations. Adding a public IP with a random hash subdomain is insecure; the hash could be discovered, and it offers no authentication mechanism.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed