Q49
Single choice
You are designing a security-focused network architecture on Google Cloud. Your company has deployed a central inspection VPC that contains a fleet of Cloud Next Generation Firewall (NGFW) appliances. The inspection VPC has a default route with next hop pointing to the passthrough Network Load Balancer with NGFW appliances as backends.
You also have two application VPCs (App-A and App-B) that are not allowed to directly communicate with each other, nor do they have a default route in their VPC. You need to ensure that all traffic originating from App-A and App-B are forced through the inspection VPC to be analyzed by the Cloud NGFW appliances.
What should you do?