Two departments in separate projects each have one VPC and need full VM-to-VM connectivity while keeping network control and minimizing cost. Neither will recreate VMs. Which two steps accomplish this?
Choose an answer
Tap an option to check your answer.
Correct answer: Connect the VPCs in project code-dev and data-dev using VPC Network Peering., Enable firewall rules to allow all ingress traffic from all subnets of project code-dev to all instances in project data-dev, and vice versa..
Why this is the answer
VPC Network Peering allows direct, private IP connectivity between VPC networks in different projects, providing full VM-to-VM connectivity without traversing the public internet, which is cost-effective and secure. However, peering alone doesn't automatically allow traffic; firewall rules are still necessary to permit the desired communication between the peered networks. Therefore, enabling firewall rules for ingress traffic between the subnets in both projects is the second crucial step to achieve full VM-to-VM connectivity. Cloud VPN is more complex and expensive for inter-VPC connectivity within Google Cloud. Shared VPC is for centralizing network administration, not for connecting existing independent VPCs without recreating VMs. Custom routes with default gateways won't establish connectivity between separate VPCs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed