Ultimate access to all questions.
To comply with your organization's security policy requiring all internet-bound traffic to route through on-premises HA VPN tunnels before egressing, while allowing VMs to access private Google APIs via the private VIP range 199.36.153.4/30, how should you configure the routes to enable these traffic flows?