Multiple client applications have dynamic public IPs and must connect to a Cloud SQL instance over public IP. You require secured connections and have enforced SSL and strong passwords. How should you configure access?
Choose an answer
Tap an option to check your answer.
Correct answer: Leave the Authorized Network empty. Use Cloud SQL Auth proxy on all applications..
Why this is the answer
The Cloud SQL Auth proxy is the recommended and most secure way to connect to Cloud SQL from dynamic IP addresses. It automatically handles encryption (SSL/TLS) and IAM authentication, eliminating the need to manage SSL certificates or authorize specific IP ranges. By leaving the Authorized Networks empty, you prevent any direct public IP access, forcing all connections through the secure proxy. Adding CIDR 0.0.0.0/0 to Authorized Networks opens your database to the entire internet, which is a significant security risk, even with SSL and strong passwords. While IAM adds user-level security, it doesn't restrict network access. Manually adding and updating all application networks is impractical and error-prone for dynamic IPs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed