QuestionQ19

Securing communications and establishing boundary protection

You need to configure a Cloud Interconnect connection between your company’s on-premises data center and a VPC host network. You want to ensure that on-premises applications can access Google APIs only over Cloud Interconnect, rather than through the public internet. You must use only APIs supported by VPC Service Controls to mitigate the risk of exfiltration to unsupported APIs. How should the network be configured?

Explanation

restricted.googleapis.com uses the restricted VIP, which is intended for APIs and services supported by VPC Service Controls and denies access to unsupported APIs. Advertising its VIP range to the on-premises network through Cloud Router over Cloud Interconnect lets on-premises requests reach Google APIs privately through the VPC rather than via the public internet.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!