Pre-Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

Professional-Cloud-Network-Engineer Google Cloud Certified - Professional Cloud Network Engineer is now Stable and With Pass Result | Test Your Knowledge for Free

Exams4sure Dumps

Professional-Cloud-Network-Engineer Practice Questions

Google Cloud Certified - Professional Cloud Network Engineer

Last Update 1 day ago
Total Questions : 233

Dive into our fully updated and stable Professional-Cloud-Network-Engineer practice test platform, featuring all the latest Google Cloud Platform exam questions added this week. Our preparation tool is more than just a Google study aid; it's a strategic advantage.

Our free Google Cloud Platform practice questions crafted to reflect the domains and difficulty of the actual exam. The detailed rationales explain the 'why' behind each answer, reinforcing key concepts about Professional-Cloud-Network-Engineer. Use this test to pinpoint which areas you need to focus your study on.

Professional-Cloud-Network-Engineer PDF

Professional-Cloud-Network-Engineer PDF (Printable)
$43.75
$124.99

Professional-Cloud-Network-Engineer Testing Engine

Professional-Cloud-Network-Engineer PDF (Printable)
$50.75
$144.99

Professional-Cloud-Network-Engineer PDF + Testing Engine

Professional-Cloud-Network-Engineer PDF (Printable)
$63.7
$181.99
Question # 51

You recently deployed two network virtual appliances in us-central1. Your network appliances provide connectivity to your on-premises network, 10.0.0.0/8. You need to configure the routing for your Virtual Private Cloud (VPC). Your design must meet the following requirements:

All access to your on-premises network must go through the network virtual appliances.

Allow on-premises access in the event of a single network virtual appliance failure.

Both network virtual appliances must be used simultaneously.

Which method should you use to accomplish this?

Options:

A.  

Configure two routes for 10.0.0.0/8 with different priorities, each pointing to separate network virtual appliances.

B.  

Configure an internal HTTP(S) load balancer with the two network virtual appliances as backends. Configure a route for 10.0.0.0/8 with the internal HTTP(S) load balancer as the next hop.

C.  

Configure a network load balancer for the two network virtual appliances. Configure a route for 10.0.0.0/8 with the network load balancer as the next hop.

D.  

Configure an internal TCP/UDP load balancer with the two network virtual appliances as backends. Configure a route for 10.0.0.0/8 with the internal load balancer as the next hop.

Discussion 0
Question # 52

You’ve received reports of latency between two application VMs which run in two different regions of your Google Cloud VPC network. There is typically about 8ms of latency, but now there is approximately 17ms of latency. You've eliminated application issues as a root cause, and you suspect that the latency may be a Google Cloud platform issue. You need to confirm this hypothesis using Google-recommended practices. What should you do?

Options:

A.  

Q Use Network Intelligence Center Performance Dashboard to view the inter-region packet loss for your VP

C.  

B.  

O Install and run tcpdump on both instances, and calculate the latency between the two instances by comparing the timestamps in the packet captures.

C.  

Q Use Network Intelligence Center Performance Dashboard to view inter-region latency for the Google Cloud network.

D.  

Q Use Network Intelligence Center Connectivity Tests, run a test between the two VMs, and review the inter-region latency in the test results.

Discussion 0
Question # 53

You are trying to update firewall rules in a shared VPC for which you have been assigned only Network Admin permissions. You cannot modify the firewall rules. Your organization requires using the least privilege necessary.

Which level of permissions should you request?

Options:

A.  

Security Admin privileges from the Shared VPC Admin.

B.  

Service Project Admin privileges from the Shared VPC Admin.

C.  

Shared VPC Admin privileges from the Organization Admin.

D.  

Organization Admin privileges from the Organization Admin.

Discussion 0
Question # 54

You are deploying GKE clusters in your organization's Google Cloud environment. The pods in these clusters need to egress directly to the internet for a majority of their communications. You need to deploy the clusters and associated networking features using the most cost-efficient approach, and following Google-recommended practices. What should you do?

Options:

A.  

Q Deploy the GKE cluster with public cluster nodes. Do not deploy Cloud NAT or Secure Web Proxy for the cluster.

B.  

Q Deploy the GKE cluster with private cluster nodes. Deploy Secure Web Proxy, and configure the pods to use Secure Web Proxy as an HTTP(S) proxy.

C.  

Q Deploy the GKE cluster with public cluster nodes. Deploy Secure Web Proxy, and configure the pods to use Secure Web Proxy as an HTTP(S) proxy.

D.  

Q Deploy the GKE cluster with private cluster nodes. Deploy Cloud NAT for the primary subnet of the cluster.

Discussion 0
Question # 55

You decide to set up Cloud NAT. After completing the configuration, you find that one of your instances is not using the Cloud NAT for outbound NAT.

What is the most likely cause of this problem?

Options:

A.  

The instance has been configured with multiple interfaces.

B.  

An external IP address has been configured on the instance.

C.  

You have created static routes that use RFC1918 ranges.

D.  

The instance is accessible by a load balancer external IP address.

Discussion 0
Question # 56

You are designing a new global application using Compute Engine instances that will be exposed by a global HTTP(S) load balancer. You need to secure your application from distributed denial-of-service and application layer (layer 7) attacks. What should you do?

Options:

A.  

Configure VPC Service Controls and create a secure perimeter. Define fine-grained perimeter controls and enforce that security posture across your Google Cloud services and projects.

B.  

Configure a Google Cloud Armor security policy in your project, and attach it to the backend service to secure the application.

C.  

Configure VPC firewall rules to protect the Compute Engine instances against distributed denial-of-service attacks.

D.  

Configure hierarchical firewall rules for the global HTTP(S) load balancer public IP address at the organization level.

Discussion 0
Question # 57

You are troubleshooting connectivity issues between Google Cloud and a public SaaS provider. Connectivity between the two environments is through the public internet. Your users are reporting intermittent connection errors when using TCP to connect; however, ICMP tests show no failures. According to users, errors occur around the same time every day. You want to troubleshoot and gather information by using Google Cloud tools that are most likely to provide insights into what is occurring within Google Cloud. What should you do?

Options:

A.  

Enable the Firewall Insights API. Set the deny rule insights observation period to one day. Review the insights to assure there are no firewall rules denying traffic.

B.  

Enable and review Cloud Logging on your Cloud NAT gateway. Look for logs with errors matching the destination IP address of the public SaaS provider.

C.  

Create a Connectivity Test by using TCP, the source IP address of your test VM, and the destination IP address of the public SaaS provider. Review the live data plane analysis and take the next steps based on the test results.

D.  

Enable and review Cloud Logging for Cloud Armor. Look for logs with errors matching the destination IP address of the public SaaS provider.

Discussion 0
Question # 58

You have the networking configuration shown. In the diagram Two VLAN attachments associated With two Dedicated Interconnect connections terminate on the same Cloud Router (mycloudrouter). The Interconnect connections terminate on two separate on-premises routers. You advertise the same prefixes from the Border Gateway Protocol (BOP) sessions associated with each Of the VLAN attachments.

You notice an asymmetric traffic flow between the two Interconnect connections. Which of the following actions should you take to troubleshoot the asymmetric traffic flow?

Question # 58

Options:

A.  

From the Google Cloud console, navigate to the Hybrid Connectivity select the Cloud Router, and view BGP sessions.

B.  

From the Cloud CLI, run gcloud compute –protect_ID router get—status mycloudrouter —-region REGION and review the results.

C.  

From the Google Cloud console, navigate to Cloud Logging to view VPC Flow Logs and review the results

D.  

From the Cloud CLI. run gcloud compute routers describe mycloudrouter

--region REGION and review the results

Discussion 0
Question # 59

You create multiple Compute Engine virtual machine instances to be used as TFTP servers.

Which type of load balancer should you use?

Options:

A.  

HTTP(S) load balancer

B.  

SSL proxy load balancer

C.  

TCP proxy load balancer

D.  

Network load balancer

Discussion 0
Question # 60

You need to configure a static route to an on-premises resource behind a Cloud VPN gateway that is configured for policy-based routing using the gcloud command.

Which next hop should you choose?

Options:

A.  

The default internet gateway

B.  

The IP address of the Cloud VPN gateway

C.  

The name and region of the Cloud VPN tunnel

D.  

The IP address of the instance on the remote side of the VPN tunnel

Discussion 0
Get Professional-Cloud-Network-Engineer dumps and pass your exam in 24 hours!

Free Exams Sample Questions