Pre-Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

Professional-Cloud-Network-Engineer Google Cloud Certified - Professional Cloud Network Engineer is now Stable and With Pass Result | Test Your Knowledge for Free

Exams4sure Dumps

Professional-Cloud-Network-Engineer Practice Questions

Google Cloud Certified - Professional Cloud Network Engineer

Last Update 1 day ago
Total Questions : 233

Dive into our fully updated and stable Professional-Cloud-Network-Engineer practice test platform, featuring all the latest Google Cloud Platform exam questions added this week. Our preparation tool is more than just a Google study aid; it's a strategic advantage.

Our free Google Cloud Platform practice questions crafted to reflect the domains and difficulty of the actual exam. The detailed rationales explain the 'why' behind each answer, reinforcing key concepts about Professional-Cloud-Network-Engineer. Use this test to pinpoint which areas you need to focus your study on.

Professional-Cloud-Network-Engineer PDF

Professional-Cloud-Network-Engineer PDF (Printable)
$43.75
$124.99

Professional-Cloud-Network-Engineer Testing Engine

Professional-Cloud-Network-Engineer PDF (Printable)
$50.75
$144.99

Professional-Cloud-Network-Engineer PDF + Testing Engine

Professional-Cloud-Network-Engineer PDF (Printable)
$63.7
$181.99
Question # 61

Question:

Your organization has a hub and spoke architecture with VPC Network Peering, and hybrid connectivity is centralized at the hub. The Cloud Router in the hub VPC is advertising subnet routes, but the on-premises router does not appear to be receiving any subnet routes from the VPC spokes. You need to resolve this issue. What should you do?

Options:

A.  

Create custom learned routes at the Cloud Router in the hub to advertise the subnets of the VPC spokes.

B.  

Create custom routes at the Cloud Router in the spokes to advertise the subnets of the VPC spokes.

C.  

Create a BGP route policy at the Cloud Router, and ensure the subnets of the VPC spokes are being announced towards the on-premises environment.

D.  

Create custom routes at the Cloud Router in the hub to advertise the subnets of the VPC spokes.

Discussion 0
Question # 62

Your organization has Compute Engine instances in us-east1, us-west2, and us-central1. Your organization also has an existing Cloud Interconnect physical connection in the East Coast of the United States with a single VLAN attachment and Cloud Router in us-east1. You need to provide a design with high availability and ensure that if a region goes down, you still have access to all your other Virtual Private Cloud (VPC) subnets. You need to accomplish this in the most cost-effective manner possible. What should you do?

Options:

A.  

Configure your VPC routing in regional mode.

Add an additional Cloud Interconnect VLAN attachment in the us-east1 region, and configure a Cloud Router in us-east1.

B.  

Configure your VPC routing in global mode.

Add an additional Cloud Interconnect VLAN attachment in the us-east1 region, and configure a Cloud Router in us-east1.

C.  

Configure your VPC routing in global mode.

Add an additional Cloud Interconnect VLAN attachment in the us-west2 region, and configure a Cloud Router in us-west2.

D.  

Configure your VPC routing in regional mode.

Add additional Cloud Interconnect VLAN attachments in the us-west2 and us-central1 regions, and configure Cloud Routers in us-west2 and us-central1.

Discussion 0
Question # 63

Your company has a security team that manages firewalls and SSL certificates. It also has a networking team that manages the networking resources. The networking team needs to be able to read firewall rules, but should not be able to create, modify, or delete them.

How should you set up permissions for the networking team?

Options:

A.  

Assign members of the networking team the compute.networkUser role.

B.  

Assign members of the networking team the compute.networkAdmin role.

C.  

Assign members of the networking team a custom role with only the compute.networks.* and the compute.firewalls.list permissions.

D.  

Assign members of the networking team the compute.networkViewer role, and add the compute.networks.use permission.

Discussion 0
Question # 64

You are responsible for enabling Private Google Access for the virtual machine (VM) instances in your Virtual Private Cloud (VPC) to access Google APIs. All VM instances have only a private IP address and need to access Cloud Storage. You need to ensure that all VM traffic is routed back to your on-premises data center for traffic scrubbing via your existing Cloud Interconnect connection. However, VM traffic to Google APIs should remain in the VP

C.  

What should you do?

Options:

A.  

Delete the default route in your VP

C.  

Create a private Cloud DNS zone for googleapis.com, create a CNAME for *.googleapis.com to restricted googleapis.com, and create an A record for restricted googleapis com that resolves to the addresses in 199.36.153.4/30.

Create a static route in your VPC for the range 199.36.153.4/30 with the default internet gateway as the next hop.

B.  

Delete the default route in your VPC and configure your on-premises router to advertise 0.0.0.0/0 via Border Gateway Protocol (BGP).

Create a public Cloud DNS zone with a CNAME for *.google.com to private googleapis com, create a CNAME for * googleapis.com to private googleapis com, and create an A record for Private googleapis.com that resolves to the addresses in 199.36.153 8/30.

Create a static route in your VPC for th

C.  

Configure your on-premises router to advertise 0.0.0.0/0 via Border Gateway Protocol (BGP) with a lower priority (MED) than the default VPC route.

Create a private Cloud DNS zone for googleapis.com, create a CNAME for * googieapis.com to private googleapis com, and create an A record for private.googleapis.com that resolves to the addresses in 199 .36.153.8/30.

Create a static route in your VPC for the range 199.36. 153.8

D.  

Delete the default route in your VPC and configure your on-premises router to advertise 0.0.0.0/0 via Border Gateway Protocol (BGP).

Create a private Cloud DNS zone for googleapis.com, create a CNAME for * googieapis.com to Private googleapis.com, and create an A record for private.googleapis.com that resolves to the addresses in 199.36.153.8/30.

Create a static route in your VPC for the range 199.36.153.8/30 with the def

Discussion 0
Question # 65

You are implementing a VPC architecture for your organization by using a Network Connectivity Center hub and spoke topology:

• There is one Network Connectivity Center hybrid spoke to receive on-premises routes.

• There is one VPC spoke that needs to be added as a Network Connectivity Center spoke.

Your organization has limited routable IP space fortheir cloud environment (192.168.0.0/20). The Network Connectivity Center spoke VPC is connected to on-premises with a Cloud Interconnect connection in the us-east4 region. The on-premises IP range is 172.16.0.0/16. You need to reach on-premises resources from multiple Google Cloud regions (us-westl, europe-centrall, and asia-southeastl) and minimize the IP addresses being used. What should you do?

Options:

A.  

O 1. Configure a Private NAT gateway and NAT subnet in us-westl (192.168.1.0/24), europe-centrall (192.168.2.0/24) and asia-southeastl (192.168.3.0/24).

2. Add the VPC as a spoke and configure an export include policy to advertise only 192.168.1.0/24, 192.168.2.0/24, and 192.168.3.0/24 to the hub.

3. Enable global dynamic routing to allow resources in us-westl, us-centrall and asia-southeastl to reach the on-premises location th

B.  

Q 1. Configure a Private NAT gateway instance in us-westl (192.168.1.0/24), europe-centrall (192.168.2.0/24), and asia-southeastl (192.168.3.0/24).

2. Add the VPC as a spoke and configure an export exclude policy on the VPC spoke to advertise only the NAT subnets 192.168.1.0/24, 192.168.2.0/24, and 192.168.3.0/24 to the hub.

3. Enable global dynamic routing to allow resources in us-westl, us-centrall, and asia-southeastl to reac

C.  

Q 1. Configure a Private NAT gateway instance in us-east4 (192.168.1.0/24).

2. Add the VPC as a spoke and configure an export include policy on the VPC spoke to advertise 192.168.1.0/24 to the hub.

3. Enable global dynamic routing to allow resources in us-westl, us-centrall and asia-southeast l to reach the on-premises location through us-east 4.

D.  

O 1- Configure a Private NAT gateway instance in us-westl (172.16.1.0/24), europe-centrall (172.16.2.0/24), and asia-southeastl (172.16.3.0/24).

2. Add the VPC as a spoke and configure an export include policy on the VPC spoke to advertise only the NAT subnets 172.16.1.0/24, 172.16.2.0/24, and 172.16.3.0/24 to the hub.

3. Enable global dynamic to allow resources in us-westl, us-centrall, and asia-southeastl to reach the on-premi

Discussion 0
Question # 66

Your company’s on-premises network is connected to a VPC using a Cloud VPN tunnel. You have a static route of 0.0.0.0/0 with the VPN tunnel as its next hop defined in the VP

C.  

All internet bound traffic currently passes through the on-premises network. You configured Cloud NAT to translate the primary IP addresses of Compute Engine instances in one region. Traffic from those instances will now reach the internet directly from their VPC and not from the on-premises network. Traffic from the virtual machines (VMs) is not translating addresses as expected. What should you do?

Options:

A.  

Lower the TCP Established Connection Idle Timeout for the NAT gateway.

B.  

Add firewall rules that allow ingress and egress of the external NAT IP address, have a target tag that is on the Compute Engine instances, and have a priority value higher than the priority value of the default route to the VPN gateway.

C.  

Add a default static route to the VPC with the default internet gateway as the next hop, the network tag associated with the Compute Engine instances, and a higher priority than the priority of the default route to the VPN tunnel.

D.  

Increase the default min-ports-per-vm setting for the Cloud NAT gateway.

Discussion 0
Question # 67

Your team is developing an application that will be used by consumers all over the world. Currently, the application sits behind a global external application load balancer You need to protect the application from potential application-level attacks. What should you do?

Options:

A.  

Enable Cloud CDN on the backend service.

B.  

Create multiple firewall deny rules to block malicious users, and apply them to the global external application load balancer

C.  

Create a Google Cloud Armor security policy with web application firewall rules, and apply the security policy to the backend service.

D.  

Create a VPC Service Controls perimeter with the global external application load balancer as the protected service, and apply it to the backend service

Discussion 0
Question # 68

You have deployed a proof-of-concept application by manually placing instances in a single Compute Engine zone. You are now moving the application to production, so you need to increase your application availability and ensure it can autoscale.

How should you provision your instances?

Options:

A.  

Create a single managed instance group, specify the desired region, and select Multiple zones for the location.

B.  

Create a managed instance group for each region, select Single zone for the location, and manually distribute instances across the zones in that region.

C.  

Create an unmanaged instance group in a single zone, and then create an HTTP load balancer for the instance group.

D.  

Create an unmanaged instance group for each zone, and manually distribute the instances across the desired zones.

Discussion 0
Question # 69

You manage two VPCs: VPC1 and VPC2, each with resources spread across two regions. You connected the VPCs with HA VPN in both regions to ensure redundancy. You’ve observed that when one VPN gateway fails, workloads that are located within the same region but different VPCs lose communication with each other. After further debugging, you notice that VMs in VPC2 receive traffic but their replies never get to the VMs in VPC1. You need to quickly fix the issue. What should you do?

Options:

A.  

Q Enable regional dynamic routing mode in VPC2.

B.  

Q Enable global dynamic routing mode in VPC1.

C.  

Q Enable global dynamic routing mode in VPC2.

D.  

Q Enable regional dynamic routing mode in VPC1.

Discussion 0
Get Professional-Cloud-Network-Engineer dumps and pass your exam in 24 hours!

Free Exams Sample Questions