Ultimate access to all questions.
Your organization, TerramEarth, is deploying a global application to handle credit card payments. Client VMs within the same VPC as the application must access it privately without using the application's global external IP address due to compliance constraints. Currently, Cloud DNS resolves myglobalapp.terramearth.com
only to a public IP address via a public zone. The internal clients need to resolve myglobalapp.example.com
privately without exposing the external IP. How should you configure Cloud DNS to meet this requirement while adhering to Google-recommended practices?