
Ultimate access to all questions.
You need to reduce the external attack surface of a Linux bastion host by removing its public IP address, while still allowing Site Reliability Engineers (SREs) to access it from public locations to reach the internal VPC. How should you provide this access?
A
Implement Cloud VPN for the region where the bastion host lives.
B
Implement OS Login with 2-step verification for the bastion host.
C
Implement Identity-Aware Proxy TCP forwarding for the bastion host.
D
Implement Google Cloud Armor in front of the bastion host.