Multiple VMs across VPCs need outbound internet access but cannot have public IPs. Only specific subnets should be allowed to use Cloud NAT, and you want to prevent accidental misconfiguration and follow Google-recommended practice. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a constraints/compute.restrictCloudNATUsage organizational policy, attach it to the folder containing the projects, set allowedValues to the allowed subnets, then deploy Cloud NAT and select only the allowed subnets..
Why this is the answer
The correct answer leverages an Organizational Policy, constraints/compute.restrictCloudNATUsage, which is the Google-recommended and most robust way to enforce restrictions on Cloud NAT usage across projects and folders. By attaching this policy to the folder and specifying allowedValues for the permitted subnets, you prevent accidental misconfiguration and ensure only designated subnets can use Cloud NAT for outbound internet access, even if someone attempts to configure it otherwise. This approach provides strong, centralized control. The firewall rule options are incorrect because firewall rules control traffic flow, not the configuration or scope of Cloud NAT itself. While they could block traffic, they don't prevent Cloud NAT from being configured for unintended subnets. Deploying Cloud NAT in each VPC with custom source ranges and rules is a partial solution but lacks the preventative, organizational-level control offered by the Organizational Policy, making it more prone to misconfiguration.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed