Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 183 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 183

Single answerGoogle Cloud Platform

Your company is deploying a private GKE cluster on Google Cloud. The security team has strict requirements to avoid exposing any cluster management endpoints to the public internet. However, the DevOps team requires seamless access to the cluster for management purposes from within their corporate network through VPN. What is the most appropriate control plane endpoint configuration for this scenario?

  1. A

    Use a private control plane endpoint and configure authorized networks for VPN-based access.

  2. B

    Use a public control plane endpoint and restrict access using authorized networks.

  3. C

    Use a private control plane endpoint and enable direct access through Cloud NAT.

  4. D

    Use a public control plane endpoint and disable authorized networks for unrestricted access.

Show answer and explanation

Correct answer: A

Explanation

To meet the security team's requirements, the control plane endpoint must not be exposed to the public internet. A private control plane endpoint ensures this, and authorized networks allow secure, restricted access for the DevOps team via their VPN. Public control plane endpoints or unrestricted access would violate the security requirements.

  • A. Correct.

    This is correct because a private control plane endpoint ensures that the cluster API server is accessible only from internal IP addresses. Configuring authorized networks allows secure access to the cluster from the corporate network via VPN.

  • B. Incorrect.

    This is incorrect because using a public control plane endpoint exposes the API server to the internet, which violates the requirement to avoid public exposure.

  • C. Incorrect.

    This is incorrect because Cloud NAT is used for outbound internet access from private resources, not for private control plane endpoint access.

  • D. Incorrect.

    This is incorrect because disabling authorized networks would allow unrestricted access, which violates the security team's requirements.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam