Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 154 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 154

Select 3Google Cloud Platform

You are designing a solution where a workload running in a custom VPC on Google Cloud needs to access a Google-managed service (such as Cloud SQL) privately. The custom VPC is peered with another VPC using VPC Network Peering. Which of the following steps are required to ensure secure and private access to the Google-managed service?

  1. A

    Configure Private Google Access in the custom VPC.

  2. B

    Enable the Service Networking API in the custom VPC.

  3. C

    Create a private connection from the custom VPC to the Google-managed service using Private Service Connect.

  4. D

    Include routes to Google’s private IP range (199.36.153.4/30) in the peered VPC.

  5. E

    Ensure that the subnet in the custom VPC has an allocated IP range for private services.

Show answer and explanation

Correct answers: A, B, E

Explanation

To allow workloads in a custom VPC to access Google-managed services privately through VPC Network Peering, you must configure Private Google Access, enable the Service Networking API, and allocate a subnet IP range for private services. These steps ensure that traffic to Google-managed services is routed securely and privately without requiring public IPs. Private Service Connect is not applicable in this scenario, and routes to Google’s private IP range are not needed when using VPC Network Peering.

  • A. Correct.

    Correct. Private Google Access is required to allow VM instances in the custom VPC to access Google APIs and services privately.

  • B. Correct.

    Correct. The Service Networking API must be enabled to establish private service access and allocate IP ranges for Google-managed services.

  • C. Incorrect.

    Incorrect. Private Service Connect is not required for accessing Google-managed services through VPC Network Peering. It is a separate solution for accessing services.

  • D. Incorrect.

    Incorrect. Routes to Google’s private IP range are not necessary when using VPC Network Peering for private access to Google-managed services.

  • E. Correct.

    Correct. The subnet in the custom VPC must have an allocated IP range specifically for private services to ensure proper routing and connectivity.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam