表示モード
画像位置
文字位置
理解度の自動記録
Q1Google Professional Cloud Network Engineer
Q1. You are building a new GKE Standard cluster.
You need to configure it so that Pods in the cluster can reach other VMs (virtual machines) located in the 192.168.0.0/24 subnet on Google Cloud using the GKE node’s source IP address.
How should you configure this?
Show answer
Correct answer: B. Keep the IP address range assigned to GKE Pods within 10.0.0.0/8. Do not set the –disable-default-snat flag.
By default, GKE performs SNAT (source NAT) on egress traffic from Pods destined for RFC 1918 private ranges outside the cluster (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), translating the source IP to the node’s IP.To reach 192.168.0.0/24 using the node’s source IP, this default SNAT must remain in effect.
By keeping the Pod range within 10.0.0.0/8 (an RFC 1918 range different from the destination) and not setting the –disable-default-snat flag, GKE performs SNAT so that the node’s IP becomes the source.
If you set the flag, the Pod’s own IP becomes the source, which does not meet the requirement.
GKE documentation – IP masquerade agent
Q2Google Professional Cloud Network Engineer
Q2. An internal application running on Compute Engine uses BigQuery to generate aggregated results and stores them in Cloud Storage.
You do not want any of the instances that run this application to have an external IP address.
Choose two methods that can achieve this. (Choose 2)
Show answer
Correct answer: A, E
For an instance without an external IP to reach Google APIs such as BigQuery and Cloud Storage, you must provide an egress path.Private Google Access is configured per subnet and cannot be set at the whole-VPC level, so the correct approach is to enable it on all subnets.
This allows access to Google APIs without an external IP.
Alternatively, creating a Cloud NAT and routing traffic through the NAT gateway achieves egress without assigning an external IP.
Option B has the wrong configuration unit for Private Google Access, Option C’s Private Services Access is for managed services, and Option D’s peering cannot be used against BigQuery.
VPC documentation – Private Google Access
Q3Google Professional Cloud Network Engineer
Q3. Your company organizes its resource hierarchy with a parent folder that contains subfolders for each business unit.
Each business unit defines its own projects and VPCs within its assigned folder and has permission to create Google Cloud firewall rules.
You do not want traffic to flow between different VPCs.
You need to block all traffic from any source, including other VPCs, while delegating only the management of intra-VPC firewall rules to each business unit.
What should you do?
Show answer
Correct answer: D. In each business unit’s folder, create two hierarchical firewall policies with two rules each. Use the higher-priority rule to match traffic from the private CIDRs assigned to that VPC with the action “goto_next,” and the lower-priority rule to block traffic from all other sources.
Hierarchical firewall policies are centrally managed at the organization or folder level and cannot be overridden by lower-level rules.To delegate only intra-VPC decisions to each business unit, set the action to “goto_next” for traffic matching that VPC’s private CIDRs, which hands off evaluation to the lower-level VPC firewall rules.
Then, with the lower-priority rule blocking other sources, you can cut off communication between VPCs.
Option C’s “allow” makes the decision final at that point and does not delegate to the business unit.
Options A and B use per-VPC rules that the business units can change, so they do not provide centralized blocking.
Cloud NGFW documentation – Hierarchical firewall policies
Q4Google Professional Cloud Network Engineer
Q4. To achieve subnet-level isolation, you want to route only the traffic of instance-A, which is in one subnet, through a security appliance (instance-B) placed in a different subnet.
How should you configure this?
Show answer
Correct answer: B. Create a more specific route than the system-generated subnet route, with the next hop set to instance-B. Attach the tag applied to instance-A.
To route only a specific instance’s traffic through the appliance, create a custom route more specific than the system-generated subnet route, with the next hop set to instance-B.By setting the network tag applied to instance-A on that route, you can limit its scope to instance-A only and avoid affecting other instances.
The system-generated subnet route cannot be deleted, so Option C is not possible; tagless Option A affects all instances; and Option D is an overly complex configuration that is unnecessary for this requirement.
VPC documentation – Routes
Q5Google Professional Cloud Network Engineer
Q5. You are deploying HA VPN on Google Cloud.
You need to enable dynamic route exchange between the on-premises gateway and Google Cloud.
The HA VPN gateway and peer VPN gateway resources have already been created.
What should you do?
Show answer
Correct answer: A. Create a Cloud Router, add a VPN tunnel, and then configure a BGP session.
To exchange routes dynamically between on-premises and Google Cloud, use BGP.By creating a Cloud Router, adding a VPN tunnel, and configuring a BGP session, route information is automatically exchanged between the two environments.
Global dynamic routing is a setting for the VPC’s route-propagation mode across the entire VPC, and is not the direct step that establishes the dynamic exchange itself.
Option D’s static routes do not provide dynamic exchange.
Option B does not require a second HA VPN gateway and does not meet the requirement.
Cloud VPN documentation – Creating HA VPN
Q6Google Professional Cloud Network Engineer
Q6. Your current network architecture has three VPC Service Controls perimeters.
• A perimeter protecting the production storage buckets (PERIMETER_PROD)
• A perimeter protecting the non-production storage buckets (PERIMETER_NONPROD)
• A perimeter containing a single VPC (VPC_ONE) (PERIMETER_VPC)
In this single VPC (VPC_ONE), IP_RANGE_PROD is assigned to the production workload subnet and IP_RANGE_NONPROD is assigned to the non-production workload subnet.
Workloads cannot be created outside these two ranges.
You need to ensure that production workloads can access only the production storage buckets and non-production workloads can access only the non-production storage buckets, while keeping the implementation effort as small as possible.
What should you do?
Show answer
Correct answer: A. Create two access levels using IP_RANGE_PROD and IP_RANGE_NONPROD, designing each access level to reference one range. Create two ingress access policies, each referencing one of the two access levels. Update PERIMETER_PROD and PERIMETER_NONPROD.
Even within the same VPC, you can distinguish production from non-production by subnet IP range.By creating two IP-range-based access levels and binding each to a perimeter with an ingress policy, you can limit the production subnet to the production buckets only and the non-production subnet to the non-production buckets only, achieving this without significantly changing the existing configuration.
Options B, C, and D involve deleting perimeters, creating new VPCs, or migrating workloads, so they require significant effort and struggle to meet the isolation requirement.
VPC Service Controls documentation – Access levels
Q7Google Professional Cloud Network Engineer
Q7. You are expanding your use of Cloud VPN between on-premises and Google Cloud, and you want to handle a volume of traffic that a single tunnel cannot process.
You need to increase the available bandwidth on Cloud VPN.
What should you do?
Show answer
Correct answer: C. Add a second on-premises VPN gateway with a different public IP address. On the existing Cloud VPN gateway, create a second tunnel that forwards the same IP ranges but points to the new on-premises gateway IP.
To increase Cloud VPN bandwidth, provide multiple tunnels and distribute traffic across them using ECMP (equal-cost multi-path).By adding a second on-premises gateway with a different public IP and creating a second tunnel on the existing Cloud VPN gateway that forwards the same IP ranges, you can distribute load across multiple tunnels and expand bandwidth.
Option A’s MTU change does not increase bandwidth.
Simply adding to the same destination IP or moving to another region is a configuration for redundancy and is not suited to this bandwidth-expansion requirement.
Cloud VPN documentation – Classic VPN topologies
Q8Google Professional Cloud Network Engineer
Q8. For your company’s WebServices team, you need to centrally manage Identity and Access Management (IAM) permissions and email distribution as efficiently as possible.
What should you do?
Show answer
Correct answer: A. Create a Google Group for the WebServices team.
By creating a Google Group and granting IAM roles to that group, you can centrally manage permissions, and since the same group also functions as an email distribution list, you can integrate permission management and email distribution most efficiently.Adding and removing members is reflected in both simply through group operations.
Creating a domain as in Options B and C is excessive and unnecessary for centralizing permissions and distribution for a single team.
Option D’s custom role is a definition of permissions and does not contribute to centralizing email distribution.
IAM documentation – Access control with groups
Q9Google Professional Cloud Network Engineer
Q9. You work in the IT department of a university and are progressing with a migration to Google Cloud.
The requirements for the cloud environment are as follows.
• 10 Gbps on-premises connectivity
• Lowest-latency access to the cloud
• Centralized network management team
A newly established department is requesting on-premises connectivity to its own project.
You want to deploy the most cost-effective interconnect solution that connects the campus to Google Cloud.
What should you do?
Show answer
Correct answer: A. Use a Shared VPC and deploy the VLAN attachment and Dedicated Interconnect in the host project.
The 10 Gbps and lowest-latency requirements call for Dedicated Interconnect.By adopting a Shared VPC and consolidating the Dedicated Interconnect and VLAN attachment in the host project, a single interconnect can be shared by all service projects, providing connectivity to each department most cost-effectively while centralizing network management.
Having a separate interconnect per project as in Options C and D leads to duplicate investment, is inefficient, and violates the centralized-management requirement.
Cloud Interconnect documentation – Using interconnects with other projects
Q10Google Professional Cloud Network Engineer
Q10. You want to apply a new Cloud Armor policy to an application deployed on Google Kubernetes Engine (GKE).
You want to confirm which GKE resource should be specified as the target of the Cloud Armor policy.
Which is the correct option?
Show answer
Correct answer: D. GKE Ingress
Cloud Armor security policies are applied to load balancers.In GKE, the Ingress resource provisions an external Application Load Balancer, so you use GKE Ingress (associated via BackendConfig) as the target of the Cloud Armor policy.
Nodes, Pods, and clusters are not load balancers, so they cannot be targets for Cloud Armor.
You configure this by combining GKE’s default Ingress controller with the security policy.
GKE documentation – Ingress features
