Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 146 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 146

Single answerGoogle Cloud Platform

Your company has an on-premises data center connected to Google Cloud via a Cloud VPN. You need to ensure that workloads in your on-premises environment can privately access Google APIs and services, such as Cloud Storage and BigQuery, without exposing traffic to the public internet. Which solution should you implement?

  1. A

    Set up Private Service Connect for Google APIs and configure DNS forwarding to Google's private zone.

  2. B

    Create a Cloud NAT gateway in Google Cloud and route on-premises traffic through it.

  3. C

    Enable VPC Service Controls and configure access policies for Google APIs.

  4. D

    Establish a Dedicated Interconnect and route all traffic to Google APIs over it.

Show answer and explanation

Correct answer: A

Explanation

Private Service Connect for Google APIs is specifically designed to allow private access to Google APIs and services from on-premises locations. By creating Private Service Connect endpoints and configuring DNS forwarding to Google's private zones, traffic between on-premises environments and Google APIs remains private and does not traverse the public internet. Other options, such as Cloud NAT, VPC Service Controls, and Dedicated Interconnect, either do not address the requirement for private API access or are not designed for this purpose.

  • A. Correct.

    This is the correct option. Private Service Connect for Google APIs allows on-premises workloads to privately access Google APIs and services through private IPs. Configuring DNS forwarding ensures that DNS queries for Google services resolve to private IPs.

  • B. Incorrect.

    This is incorrect. Although Cloud NAT enables private outbound internet access for resources in Google Cloud, it does not facilitate private access to Google APIs from on-premises locations.

  • C. Incorrect.

    This is incorrect. VPC Service Controls enhance security for API access but do not provide the mechanism to privately access Google APIs from on-premises environments.

  • D. Incorrect.

    This is incorrect. Dedicated Interconnect provides private connectivity to Google Cloud resources, but it does not inherently enable private access to Google APIs and services.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam