How to Secure a 3-Tier App with VPC Peering and IAP?

Network Security & Identity Management
Answer Correct answer: C — Create separate VPC networks for each tier, peer them for controlled traffic, and enable Identity-Aware Proxy for secure, least-privilege vendor remote access.

You work for an ecommerce company that stores sensitive customer data across multiple Google Cloud regions. The development team has built a new 3-tier application to process orders and must integrate the application into the production environment. You must design the network architecture to ensure strong security boundaries and isolation for the new application, facilitate secure remote maintenance by authorized third-party vendors, and follow the principle of least privilege. What should you do?

  1. Create separate VPC networks for each tier. Use VPC peering between application tiers and other required VPCs. Provide vendors with SSH keys and root access only to the instances within the VPC for maintenance purposes.
  2. Create a single VPC network and create different subnets for each tier. Create a new Google project specifically for the third-party vendors and grant the network admin role to the vendors. Deploy a VPN appliance and rely on the vendors’ configurations to secure third-party access.
  3. Create separate VPC networks for each tier. Use VPC peering between application tiers and other required VPCs. Enable Identity-Aware Proxy (IAP) for remote access to management resources, limiting access to authorized vendors. Correct Answer
  4. Create a single VPC network and create different subnets for each tier. Create a new Google project specifically for the third-party vendors. Grant the vendors ownership of that project and the ability to modify the Shared VPC configuration.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the architectural trade-off between network segmentation and secure remote access, with the common trap being direct SSH exposure instead of identity-aware proxy solutions.

This scenario tests micro-segmentation using isolated VPCs and secure remote administration via Identity-Aware Proxy on Google Cloud. The page establishes that option C correctly balances strict network isolation, controlled inter-tier traffic, and least-privilege vendor access.

Candidates frequently select direct SSH or root access options because they prioritize immediate convenience over security, overlooking how IAP eliminates port exposure and enforces granular IAM controls.

Community Discussion (3 comments)

Pime13 👍 1 Selected: C
This approach ensures that each tier of the application is isolated within its own VPC, enhancing security. VPC peering allows necessary communication between tiers while maintaining isolation. Using Identity-Aware Proxy (IAP) for remote access ensures that only authorized vendors can access management resources, adhering to the principle of least privilege.
json4u 👍 1 Selected: C
It's C.
abdelrahman89 👍 2
C - Separate VPCs: Creating separate VPC networks for each tier provides a strong isolation boundary, reducing the risk of unauthorized access or lateral movement. VPC Peering: Using VPC peering between application tiers and other required VPCs allows for secure communication while maintaining isolation. Identity-Aware Proxy (IAP): Enabling IAP for remote access to management resources provides a secure and controlled way for authorized vendors to access the application. IAP requires authentication and authorization, ensuring that only authorized individuals can access the resources. Least Privilege: This approach adheres to the principle of least privilege by granting vendors only the necessary access to perform their maintenance tasks.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Creating separate VPC networks for each application tier establishes hard security boundaries that effectively contain potential breaches and prevent lateral movement. VPC peering enables necessary inter-tier communication while maintaining these strict isolation controls. Enabling Identity-Aware Proxy replaces traditional SSH endpoints with a secure, identity-based tunnel that verifies user credentials before granting instance access, perfectly satisfying the requirement for authorized third-party maintenance under the principle of least privilege.

Why the Other Options Are Wrong

Option A exposes management ports directly and grants dangerous root privileges, which blatantly violates least privilege and increases attack surface. Option B relies on a flat single-VPC architecture that lacks true isolation and incorrectly assigns broad network administrator roles to external vendors. Option D compounds these flaws by granting full project ownership and Shared VPC configuration rights, creating an unacceptable privilege escalation risk for third parties.

Community Comment Notes

As abdelrahman89 noted, "Creating separate VPC networks for each tier provides a strong isolation boundary," highlighting the necessity of micro-segmentation. Pime13 emphasized that using Identity-Aware Proxy ensures only authorized personnel can reach management resources while strictly adhering to least privilege. Another contributor simply confirmed the selection, reinforcing that this combination of VPC isolation and proxy-based access represents the industry-standard approach for secure cloud deployments.

Official Reference

Exam Strategy

Scan the prompt for keywords like "strong security boundaries," "isolation," and "principle of least privilege" to immediately eliminate flat networking models and overly permissive IAM assignments. Always default to managed identity proxies like IAP over direct SSH or root access when designing secure remote maintenance workflows for third parties.

Frequently Asked Questions

Why not use direct SSH keys for vendor maintenance?

Direct SSH exposes management ports to the internet and requires elevated privileges, violating least privilege. IAP proxies traffic through Google’s infrastructure using granular IAM policies instead.

Why is a single VPC with subnets insufficient here?

Subnets lack hard network-level isolation and cannot prevent lateral movement during a breach. Separate VPCs create distinct security boundaries required for sensitive ecommerce data.

Related Analysis

← Back to PCSE Study Guide