Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 177 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 177

Single answerGoogle Cloud Platform

You are designing a Google Kubernetes Engine (GKE) cluster for a financial services application that must comply with strict regulatory requirements. The application processes sensitive customer data, and the regulatory standards mandate that sensitive data must not traverse public networks. However, the application also needs to occasionally connect to internet services for software updates. Which setup should you choose for your cluster nodes and node pools?

  1. A

    Use private nodes with Cloud NAT to allow internet access for updates.

  2. B

    Use public nodes with restrictive firewall rules to block access to public IPs.

  3. C

    Use private nodes with no internet access and manually transfer updates.

  4. D

    Use public nodes and enable Shielded VM for enhanced security.

Show answer and explanation

Correct answer: A

Explanation

Private nodes in GKE ensure that the cluster nodes do not have public IP addresses, keeping sensitive data within the private network. To allow controlled internet access for updates, Cloud NAT can be used to enable outbound traffic without exposing the nodes to the public internet. This setup meets the regulatory requirements for keeping sensitive data secure while still allowing the cluster to function efficiently.

  • A. Correct.

    This is the correct answer because private nodes ensure that sensitive data stays within the private network while Cloud NAT allows secure and controlled access to the internet for activities like software updates.

  • B. Incorrect.

    While public nodes can be secured using firewall rules, they still have public IP addresses, which do not meet the regulatory requirement of avoiding public networks for sensitive data.

  • C. Incorrect.

    This option meets the regulatory requirement but is not practical because it introduces significant operational overhead for managing updates manually.

  • D. Incorrect.

    While Shielded VM enhances security, public nodes with public IPs do not comply with the regulatory requirement of avoiding public networks for sensitive data.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam