Your company has recently installed a Cloud VPN tunnel between your on-premises data center and your Google Cloud Virtual Private Cloud (VPC). You need to configure access to the Cloud Functions API for your on-premises servers. The configuration must meet the following requirements: • Certain data must stay in the project where it is stored and not be exfiltrated to other projects. • Traffic from servers in your data center with RFC 1918 addresses do not use the internet to access Google Cloud APIs. • All DNS resolution must be done on-premises. • The solution should only provide access to APIs that are compatible with VPC Service Controls. What should you do?