Ultimate access to all questions.
You are using a third-party next-generation firewall to inspect traffic and have created a custom route (0.0.0.0/0) to route egress traffic to the firewall. You need to allow VPC instances without public IP addresses to access the BigQuery and Cloud Pub/Sub APIs directly, bypassing the firewall.
Which two actions should you take? (Choose two.)