Google Associate Cloud Engineer exam dumps

Google Associate Cloud Engineer practice question 277 of 375

Associate Cloud Engineer. Free level, Google Cloud. Free question with the correct answer and a full explanation.

Google Associate Cloud Engineer Question 277

Select 3Google Cloud Platform

You are managing a Google Cloud project for a company that has a hybrid cloud setup. The company needs to ensure that their on-premises systems can resolve domain names for services hosted in Google Cloud, and also that their Google Cloud instances can access the internet securely without exposing their private IPs. Which of the following steps should you take to achieve this setup?

  1. A

    Configure Cloud DNS with a private zone and set up DNS peering between the on-premises network and the Google Cloud VPC.

  2. B

    Set up a Cloud NAT gateway to allow Google Cloud instances in the private subnet to access the internet.

  3. C

    Create a public zone in Cloud DNS for the on-premises networks to resolve Google Cloud service names.

  4. D

    Use a VPN to connect the on-premises network directly to the Google Cloud VPC.

  5. E

    Enable IP forwarding on Google Cloud instances to allow them to act as NAT devices.

Show answer and explanation

Correct answers: A, B, D

Explanation

To meet the company's requirements, you must ensure that the on-premises systems can resolve internal Google Cloud service names and that Google Cloud instances can access the internet securely. Configuring a private zone with DNS peering and using a VPN establishes the necessary connections and name resolution capabilities. Additionally, a Cloud NAT gateway allows instances to access the internet without exposing private IPs, making the setup secure and efficient.

  • A. Correct.

    Configuring Cloud DNS with a private zone and setting up DNS peering is necessary to allow on-premises systems to resolve internal Google Cloud service names.

  • B. Correct.

    Setting up a Cloud NAT gateway allows instances in a private subnet to access the internet securely without revealing their private IP addresses.

  • C. Incorrect.

    Creating a public zone is not necessary as the requirement is to resolve internal names, not to expose them publicly.

  • D. Correct.

    Using a VPN is a common approach to securely connect on-premises networks to Google Cloud, facilitating DNS peering and other network communications.

  • E. Incorrect.

    Enabling IP forwarding on instances for NAT is not recommended when Cloud NAT is available, as it is more secure and manageable.

Timed practice exam

Take a Google Associate Cloud Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam