Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 162 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 162

Single answerGoogle Cloud Platform

Your organization is running workloads in two separate VPC networks: 'VPC-A' and 'VPC-B.' Both VPCs require access to a private DNS zone hosted in 'VPC-C.' You need to design a DNS peering and forwarding strategy to ensure that VPC-A and VPC-B can resolve DNS queries for the private zone in VPC-C. Which approach should you recommend?

  1. A

    Set up DNS peering between VPC-A and VPC-C, and another DNS peering between VPC-B and VPC-C.

  2. B

    Configure Cloud DNS forwarding rules in VPC-A and VPC-B that forward queries for the private zone to the Cloud DNS forwarding target in VPC-C.

  3. C

    Create a single DNS peering zone in VPC-C that allows both VPC-A and VPC-B to resolve DNS queries for the private zone.

  4. D

    Use a centralized DNS resolver in VPC-C and configure private DNS forwarding rules in VPC-A and VPC-B to forward DNS queries to the resolver.

Show answer and explanation

Correct answer: A

Explanation

The best solution for enabling DNS resolution across VPCs for a private DNS zone is to use DNS peering. DNS peering allows VPCs to resolve private DNS zones hosted in another VPC. In this scenario, you would set up DNS peering between VPC-A and VPC-C, and also between VPC-B and VPC-C, as DNS peering is one-to-one and cannot be shared across multiple VPCs. Other solutions, such as Cloud DNS forwarding rules or centralized DNS resolvers, are either not applicable or unnecessarily complex for this use case.

  • A. Correct.

    This is the correct approach. DNS peering allows VPC networks to resolve private DNS zones across network boundaries. By setting up DNS peering between VPC-A and VPC-C, and another between VPC-B and VPC-C, both VPCs will be able to resolve queries for the private zone in VPC-C.

  • B. Incorrect.

    This is incorrect because Cloud DNS forwarding rules cannot directly forward queries to another VPC’s private DNS zone. Forwarding rules are used for sending queries to specified target IPs, such as an on-premises DNS server or a Cloud DNS forwarding target.

  • C. Incorrect.

    This is incorrect because a single DNS peering zone cannot serve multiple VPCs. DNS peering is a one-to-one relationship between two VPCs.

  • D. Incorrect.

    This is incorrect because using a centralized DNS resolver would require additional infrastructure, such as a VM-based DNS server, which is not necessary for this scenario when DNS peering is sufficient.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam