Google

Professional Cloud Network Engineer Free Practice Questions — Page 4

Question 28

Your organization has over 250 autonomous business units that currently operate in a decentralized manner. Due to the organization's maturity, there is limited routable private IP address space, which is insufficient to accommodate all of the necessary workloads. You need to create a cloud-first network design that uses the same IP address space across business unit workloads where possible. These business units require communication between units, and access to their on-premises data center. What should you do?

A. Create a hub and spoke model that incorporates VPC Network Peering with hybrid connectivity centralized within the hub.
B. Create a Network Connectivity Center design that incorporates Private NAT to facilitate communication between VPC spokes, and a Routing VPC to exchange dynamic routes from the on-premises environment.
C. Create a Network Connectivity Center design that incorporates Private Service Connect to provide bidirectional communication between VPC spokes, and a Routing VPC to exchange dynamic routes from the on-premises environment.
D. Create a hub and spoke design that incorporates a centralized network virtual appliance (NVA) in the hub to perform routing and NAT between spokes.
Show Answer
Correct Answer: B
Explanation:
The requirements include hundreds of autonomous VPCs, overlapping/limited private IP space, inter–business unit communication, and hybrid connectivity to on‑premises. Network Connectivity Center provides a scalable, Google‑recommended hub for large multi‑VPC designs. Private NAT enables communication between VPCs that reuse the same IP ranges, solving the overlapping address problem. A dedicated routing VPC allows dynamic route exchange with the on‑premises environment. Other options either do not handle overlapping IP space (VPC peering), do not support general bidirectional VPC‑to‑VPC communication (Private Service Connect), or rely on less scalable, appliance‑based designs (NVA).

Question 29

You have recently taken over responsibility for your organization's Google Cloud network security configurations. You want to review your Cloud Next Generation Firewall (Cloud NGFW) configurations to ensure that there are no rules allowing ingress traffic to your VMs and services from the internet. You want to avoid manual work. What should you do?

A. Export all your Cloud NGFW rules into a CSV file and search for 0.0.0.0/0.
B. Use Firewall Insights, and enable insights for Overly permissive rules.
C. Run Connectivity Tests from multiple external sources to confirm that traffic is not allowed to ingress to your most critical services in Google Cloud.
D. Review Network Analyzer insights on the VPC network category.
Show Answer
Correct Answer: B
Explanation:
Firewall Insights automatically analyzes Cloud NGFW rules and flags overly permissive ingress configurations (such as rules allowing traffic from the internet). This provides an automated, scalable review without manual inspection or ad hoc testing, directly matching the requirement to avoid manual work.

Question 30

Your organization's application is running on a VPC-native GKE Standard cluster with public IP addresses. You need to configure access to the remote address range 35.100.0.0/16 through Cloud NAT, instead of using the GKE nodes' external IP addresses. SNAT is enabled on the cluster and needs to be configured. What should you do?

A. Configure nonMasqueradeCIDRs in the ip-masq-agent ConfigMap. Include the 35.100.0.0/16 range in the list.
B. Configure nonMasqueradeCIDRs in the ip-masq-agent ConfigMap. Remove the 35.100.0.0/16 range from the list.
C. Configure Cloud NAT and create an exclusion rule for any SNAT address translation.
D. Configure Cloud NAT with nonMasqueradeCIDRs, and enable SNAT with the same configuration to allow traffic to 35.100.0.0/16.
Show Answer
Correct Answer: B
Explanation:
To force egress traffic to use Cloud NAT instead of the GKE nodes’ external IPs, SNAT must occur on the nodes so Cloud NAT can translate it. In GKE, the ip-masq-agent’s nonMasqueradeCIDRs defines destinations that should NOT be SNATed by the node. If 35.100.0.0/16 were included there, traffic to that range would bypass SNAT and exit using the node’s external IP, which is the opposite of the requirement. Therefore, you must ensure 35.100.0.0/16 is not in nonMasqueradeCIDRs, allowing SNAT and enabling Cloud NAT to be used.

Question 31

You are configuring a Cross-Cloud Interconnect connection for your Google Cloud organization with two public cloud service providers (CSPs)–CSP 1 and CSP 2. The CSP 1 and CSP 2 environments are closest to Frankfurt, Germany. You can choose between two common colocation locations, Frankfurt and Munich. Your organization's Google Cloud infrastructure is deployed in the North American region, us-east4, which is located in Virginia, USA. The VPC dynamic routing mode has been set to GLOBAL. Your organization requires 20 Gbps of protected bandwidth with a 99.9% Google Cloud SLA. You want to minimize costs where possible. What should you do?

A. 1. Create two Cross-Cloud Interconnect connections to CSP 1, with 40 Gbps of total bandwidth (20 Gbps in zone 1 and 20 Gbps in zone 2) in a common co-location facility located in Frankfurt, Germany. 2. Create two Cross-Cloud Interconnect connections to CSP 2, with 40 Gbps of total bandwidth (20 Gbps in zone 1 and 20 Gbps in zone 2) in a common co-location facility located in Frankfurt, Germany. 3. Create a Cloud Router in europe-west3 (Frankfurt), and configure two VLAN attachments for CSP 1 and two VLAN attachments for CSP 2.
B. 1. Create two Cross-Cloud Interconnect connections to CSP 1, with 20 Gbps of total bandwidth (10 Gbps in zone 1 and 10 Gbps in zone 2) in a common co-location facility located in Frankfurt, Germany. 2. Create two Cross-Cloud Interconnect connections to CSP 2, with 20 Gbps of total bandwidth (10 Gbps in zone 1 and 10 Gbps in zone 2) in a common co-location facility located in Frankfurt, Germany. 3. Create a Cloud Router in europe-west3 (Frankfurt), and configure two VLAN attachments for CSP 1 and two VLAN attachments for CSP 2.
C. 1. Create two Cross-Cloud Interconnect connections to CSP 1, with 40 Gbps of total bandwidth (20 Gbps in zone 1) in a common co-location facility located in Frankfurt, Germany and (20 Gbps in zone 2) in a common co-location facility located in Munich, Germany. 2. Create two Cross-Cloud Interconnect connections to CSP 2, with 40 Gbps of total bandwidth (20 Gbps in zone 1) in a common co-location facility located in Frankfurt, Germany and (20 Gbps in zone 2) in a common co-location facility located in Munich, Germany. 3. Create a Cloud Router in europe-west3 (Frankfurt), and configure two VLAN attachments for CSP 1 and two VLAN attachments for CSP 2.
D. 1. Create two Cross-Cloud Interconnect connections to CSP 1, with 40 Gbps of total bandwidth (20 Gbps in zone 1 and 20 Gbps in zone 2) in a common co-location facility located in Frankfurt, Germany. 2. Create two Cross-Cloud Interconnect connections to CSP 2, with 40 Gbps of total bandwidth (20 Gbps in zone 1 and 20 Gbps in zone 2) in a common co-location facility located in Frankfurt, Germany. 3. Create a Cloud Router in us-east4 (Ashburn, Virginia, USA), and configure two VLAN attachments for CSP 1 and two VLAN attachments for CSP 2.
Show Answer
Correct Answer: B
Explanation:
You need 20 Gbps of protected bandwidth with a 99.9% SLA, which is met by deploying redundant Cross-Cloud Interconnect connections across two edge availability zones. Using 10 Gbps per zone (total 20 Gbps) per CSP is sufficient and minimizes cost; provisioning 40 Gbps would be unnecessary. Since both CSPs are closest to Frankfurt, using a single common colocation there avoids extra cost and complexity compared to adding Munich. Cloud Routers must be created in the same region as the VLAN attachments, so europe-west3 (Frankfurt) is required. With GLOBAL dynamic routing enabled, routes learned in europe-west3 are available to us-east4, so no Cloud Router is needed in Virginia.

Question 32

Your organization deployed a mission critical application that is expected to be a new revenue source. As part of the planning and deployment process, you have recently implemented a security profile with the default set of threat signatures provided by Cloud Next Generation Firewall (Cloud NGFW). This application is the only application running on this project. You need to increase the security posture of the application to log the threat and drop the related packets. What should you do?

A. Configure a new default threat signature with Deny All to all severity options. Review the logs to understand the impact.
B. Set up a Linux VM as the frontend gateway for the application. Create iptables rules to drop all packets, excluding the application port.
C. For all severity options (critical, high, medium, low and informational) in the security profile, change the default override action to Deny.
D. Configure Cloud Scheduler to run a task that checks the Cloud NGFW logs to verify the threats. Configure the task to create a security profile with each signature ID set to override the default action.
Show Answer
Correct Answer: C
Explanation:
The requirement is to increase security posture so that threats are logged and the related packets are dropped using Cloud NGFW’s existing threat prevention framework. In Cloud NGFW, setting the action to Deny both logs the threat and drops the packet. The correct way to apply this globally is to change the default override action to Deny for all threat severity levels (critical through informational) in the existing security profile. The other options either introduce unnecessary architecture changes, are operationally complex, or misunderstand how default overrides work.

Question 33

Your organization has a legacy VPN device that uses IKEv1 and does not support BGP. Connectivity from your on-premises environment to Google Cloud needs to be established. You are using 172.16.100.0/24, 172.16.101.0/24, and 172.16.102.0/24 in your on-premises environment, and 192.168.100.0/24, 192.168.101.0/24, and 192.168.102.0/24 in your Google Cloud environment. You have configured a VPN gateway and you need to configure a policy-based VPN tunnel. What should you do?

A. Configure the tunnel with LOCAL_TS set to 172.16.100.0/22 and REMOTE_TS set to 192.168.100.0/22.
B. Configure the tunnel with LOCAL_TS set to 192.168.100.0/22 and REMOTE_TS set to 172.16.100.0/22.
C. Configure the tunnel with LOCAL_TS set to 172.16.100.0/24, 172.16.101.0/24, and 172.16.102.0/24, and REMOTE_TS set to 192.168.100.0/24,192.168.101.0/24, and 192.168.102.0/24.
D. Configure the tunnel with LOCAL_TS set to 172.16.100.0/24, 172.16.101.0/24, and 172.16.102.0/24, and REMOTE_TS set to 0.0.0.0/0.
Show Answer
Correct Answer: B
Explanation:
With IKEv1, Google Cloud VPN supports only a single local traffic selector (LOCAL_TS) and a single remote traffic selector (REMOTE_TS). Therefore, the multiple /24 subnets on each side must be summarized into a single CIDR (/22). In Cloud VPN, LOCAL_TS represents Google Cloud CIDR ranges and REMOTE_TS represents on‑premises CIDR ranges, so LOCAL_TS must be 192.168.100.0/22 and REMOTE_TS must be 172.16.100.0/22.

Question 34

Your organization has a hub and spoke architecture with VPC Network Peering, and hybrid connectivity is centralized at the hub. The Cloud Router in the hub VPC is advertising subnet routes, but the on-premises router does not appear to be receiving any subnet routes from the VPC spokes. You need to resolve this issue. What should you do?

A. Create custom routes at the Cloud Router in the spokes to advertise the subnets of the VPC spokes.
B. Create custom routes at the Cloud Router in the hub to advertise the subnets of the VPC spokes.
C. Create a BGP route policy at the Cloud Router, and ensure the subnets of the VPC spokes are being announced towards the on-premises environment.
D. Create custom learned routes at the Cloud Router in the hub to advertise the subnets of the VPC spokes.
Show Answer
Correct Answer: B
Explanation:
In a hub-and-spoke VPC peering design with centralized hybrid connectivity, Cloud Router only advertises routes from the VPC it belongs to. Spoke VPC subnet routes learned via VPC peering are not automatically advertised to on‑premises. To make spoke subnets reachable, you must configure custom route advertisements on the hub Cloud Router that explicitly include the spoke VPC CIDR ranges. Route policies alone do not create advertisements, and routes cannot be advertised from spoke Cloud Routers in this centralized model.

Question 35

You are implementing hybrid connectivity between your company's data center and Google Cloud. You've already deployed redundant Dedicated Interconnect connections, and are now deploying VLAN attachments in us-central1. You want to use an active/passive approach, where interconnect-1 is active and interconnect-2 is a passive backup. You need to deploy a Cloud Router to enable BGP connectivity. You want to follow Google-recommended practices. What should you do?

A. 1. Configure the primary interconnect-1 BGP session on the Cloud Router with priority 0 and ASN 65101. 2. Configure the secondary interconnect-2 BGP session on the Cloud Router with priority 200 and ASN 65102. 3. Configure the on-premises ASN as 65000.
B. 1. Configure the primary interconnect-1 BGP session on the Cloud Router with priority 0. 2. Configure the secondary interconnect-2 BGP session on the Cloud Router with priority 200. 3. Configure both Google-side BGP ASNs as 65100. 4. Configure the on-premises ASN as 65000.
C. 1. Configure the primary and secondary interconnects of the BGP sessions on the Cloud Router with priority 100 and ASN 16550. 2. Configure the on-premises ASN as 65001 for primary interconnect-1. 3. Configure the on-premises ASN as 65002 for secondary interconnect-2.
D. 1. Configure the primary and secondary interconnects of the BGP sessions on the Cloud Router with priority 100 and ASN 4200000001. 2. Configure the on-premises ASN as 4200000010. 3. Disable the BGP session on the on-premises router for the secondary interconnect-2.
Show Answer
Correct Answer: B
Explanation:
Google recommends using a single Google-side ASN per Cloud Router and controlling active/passive behavior with BGP session priority. Setting a lower priority (0) on interconnect-1 and higher priority (200) on interconnect-2 makes interconnect-1 preferred. Using the same Google ASN (e.g., 65100) on both sessions and a consistent on‑premises ASN (65000) follows best practices for Dedicated Interconnect with Cloud Router.

Question 36

Your organization requires that all SMTP traffic to your cloud environment is blocked, except for traffic that originates from your corporate network. Your organization also requires that only specific VPCs across your Google Cloud projects will allow SMTP access from your corporate network. You need to configure a security policy that will enable this connectivity. What should you do?

A. 1. Configure an ingress hierarchical firewall rule with priority 10000 specifying the 0.0.0.0/0 source, TCP port 25, and the deny action. 2. Configure an egress hierarchical firewall rule with priority 10010 specifying the source of your corporate network as TCP port 25 and the goto_next action. 3. Associate the hierarchical firewall policy at the organization level. 4. Configure firewall policy rules allowing TCP port 25 in the firewall policies associated with the respective VPCs that require that access.
B. 1. Configure an ingress hierarchical firewall rule with priority 10000 specifying the 0.0.0.0/0 source, TCP port 25, and the allow action. 2. Associate the hierarchical firewall policy at the organization level. 3. Configure firewall policy rules to deny TCP port 25 in the firewall policies associated with the respective VPCs that do not require that access.
C. 1. Configure an ingress hierarchical firewall rule with priority 10000 specifying the source of your corporate network, TCP port 25, and the goto_next action. 2. Configure an ingress hierarchical firewall rule with priority 10010 specifying the 0.0.0.0/0 source, TCP port 25, and the deny action. 3. Associate the hierarchical firewall policy at the organization level. 4. Configure firewall policy rules allowing TCP port 25 in the firewall policies associated with the respective VPCs that require that access.
D. 1. Configure an ingress hierarchical firewall rule with priority 10000 specifying the 0.0.0.0/0 source, TCP port 25, and the deny action. 2. Associate the hierarchical firewall policy at the organization level. 3. Configure firewall policy rules allowing TCP port 25 in the firewall policies associated with the respective VPCs that require that access.
Show Answer
Correct Answer: C
Explanation:
The requirement is to block all SMTP (TCP 25) traffic to Google Cloud by default, allow it only when it originates from the corporate network, and then permit it only in specific VPCs. This is best achieved with hierarchical firewall policies. An ingress hierarchical rule with higher priority uses goto_next for the corporate source so evaluation continues to lower-level (VPC) firewall policies. A subsequent org-level ingress rule denies TCP 25 from all other sources. The policy is attached at the organization level, and only the VPCs that need SMTP explicitly allow TCP 25 in their own firewall policies. This enforces an organization-wide deny-by-default while enabling selective VPC-level access.

Question 37

Your company uses web application firewall (WAF) capabilities from a third-party cloud WAF provider. This WAF provider proxies all the HTTPS connections from internet clients, applies security policies, and then opens a new HTTPS connection to the public IP address of your global Application Load Balancer in Google Cloud. Your Google Cloud workloads are the backend of this global Application Load Balancer. Currently, Cloud Am1or is not configured. You need to create a Cloud Armor security policy that blocks sessions that originate from internet clients with source IP addresses that belong to the IP_RANGE_BLOCK IP range. The block must be executed by the Cloud Armor security policy; it will not be done by the third-party cloud WAF provider. Whal should you do?

A. 1. Create a new Cloud Armor network edge security policy. In the policy, set the userIpRequestHeaders[] attribute. 2. Add a policy rule that denies traffic that matches inIpRange(origin.user_ip, 'IP_RANGE_BLOCK') statement. 3. Apply the policy to the backend service that includes all your Google Cloud workloads.
B. 1. Create a new Cloud Armor network edge security policy. In the policy, set the userIpRequestHeaders[] attribute. 2. Add a policy rule that denies traffic that matches the inIpRange(origin.ip, 'IP_RANGE_BLOCK') statement. 3. Apply the policy to the backend service that includes all your Google Cloud workloads.
C. 1. Create a new Cloud Armor backend security policy. In the policy, set the userIpRequestHeaders[] attribute. 2. Add a policy rule that denies traffic that matches the inIpRange(origin.user_ip, 'IP_RANGE_BLOCK') statement. 3. Apply the policy to the backend service that includes all your Google Cloud workloads.
D. 1. Create a new Cloud Armor backend security policy. In the policy, set the userIpRequestHeaders[] attribute. 2. Add a policy rule that denies traffic that matches the inIpRange(origin.ip, 'IP_RANGE_BLOCK') statement. 3. Apply the policy to the backend service that includes all your Google Cloud workloads.
Show Answer
Correct Answer: C
Explanation:
The third-party WAF terminates client connections and opens new HTTPS connections to the Google Cloud Application Load Balancer, so Cloud Armor sees the WAF IP as the source (origin.ip). To block based on the original client IP, Cloud Armor must evaluate the forwarded client IP provided in headers (for example X-Forwarded-For), which is accessed via origin.user_ip and requires configuring userIpRequestHeaders[]. Because the protection is for workloads behind a global Application Load Balancer, a Cloud Armor backend security policy must be used (not a network edge policy). Therefore, create a backend security policy, configure userIpRequestHeaders[], and deny traffic matching inIpRange(origin.user_ip, 'IP_RANGE_BLOCK').

$19

Get all 248 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.