Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 184 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 184

Single answerGoogle Cloud Platform

Your company is deploying a private GKE cluster for its internal applications and is deciding between using public or private control plane endpoints. The cluster's nodes need to access the control plane, and the engineering team has strict security requirements to limit exposure of the control plane to the public internet. Which control plane endpoint option should you recommend?

  1. A

    Public control plane endpoint with authorized networks

  2. B

    Public control plane endpoint without authorized networks

  3. C

    Private control plane endpoint with Cloud NAT for node access

  4. D

    Private control plane endpoint without additional networking setup

Show answer and explanation

Correct answer: C

Explanation

To meet the strict security requirements and avoid exposing the control plane to the public internet, a private control plane endpoint is the best choice. However, since nodes require access to the control plane, using a private control plane endpoint with Cloud NAT ensures secure communication without public IP exposure. Other options either lack security or fail to provide necessary connectivity.

  • A. Incorrect.

    Public control plane endpoint with authorized networks allows you to restrict access to the control plane by specifying CIDR ranges, but it still exposes the control plane to the public internet, which violates the strict security requirements.

  • B. Incorrect.

    Public control plane endpoint without authorized networks leaves the control plane fully open to the public internet, which is a significant security risk and does not align with the company's strict security requirements.

  • C. Correct.

    Private control plane endpoint with Cloud NAT for node access ensures that the control plane is not exposed to the public internet. Cloud NAT allows the nodes to communicate with the private control plane without requiring a public IP, meeting the security requirements effectively.

  • D. Incorrect.

    Private control plane endpoint without additional networking setup would block node access to the control plane unless specific routing or NAT configurations are implemented, which would lead to communication failures.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam