You must deploy a new Compute Engine VM on a VPC connected to your WAN via VPN and ensure it cannot receive traffic from the public Internet. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create the instance without a public IP address..
Why this is the answer
Creating the instance without a public IP address is the correct solution because it directly prevents the VM from being reachable from the public internet. By default, VMs without external IP addresses can only communicate with other instances in the same VPC network or through a VPN/interconnect. Private Google Access allows VMs without public IPs to reach Google APIs and services, but it doesn't prevent public internet ingress if the VM had a public IP. A deny-all egress firewall rule would block outbound traffic, not inbound public internet traffic. Creating a route to send all traffic over a VPN tunnel is for outbound traffic routing and doesn't inherently block public internet ingress to the VM itself.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed