Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 206 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 206

Select 2Google Cloud Platform

Your company is designing a new application that will run on Google Cloud and requires multiple microservices to communicate securely within the same Virtual Private Cloud (VPC). However, some services need to be isolated in their own subnet for compliance reasons, while others need to access external APIs over the internet. What is the most appropriate configuration to meet these requirements?

  1. A

    Create multiple subnets within the VPC, each corresponding to a specific microservice, and use firewall rules to control traffic between them.

  2. B

    Enable Private Google Access for all subnets to allow access to Google APIs without using public IP addresses.

  3. C

    Use Shared VPC to isolate microservices into different projects, and configure subnet-level IAM policies for access control.

  4. D

    Set up Cloud NAT for subnets that need internet access without exposing their resources to external networks.

  5. E

    Configure a single large subnet for all microservices to simplify management and use default firewall rules.

Show answer and explanation

Correct answers: A, D

Explanation

To meet the application's requirements, you should create multiple subnets to isolate microservices for compliance and use Cloud NAT to allow secure internet access for subnets that need to interact with external APIs. This configuration ensures both security and compliance while enabling the necessary functionality. A single large subnet or enabling Private Google Access alone would not meet all requirements, and Shared VPC is not directly relevant to this scenario.

  • A. Correct.

    Correct: Creating multiple subnets allows you to isolate microservices for compliance purposes, and firewall rules can be used to control traffic between them securely.

  • B. Incorrect.

    Incorrect: While enabling Private Google Access is useful for accessing Google APIs without public IP addresses, it does not address the need for isolation or external API access over the internet.

  • C. Incorrect.

    Incorrect: Shared VPC is primarily used to share VPC resources across multiple projects. However, it does not directly address the requirement of subnet-level isolation or internet access.

  • D. Correct.

    Correct: Cloud NAT enables resources in private subnets to access the internet securely without exposing them to incoming traffic, making it suitable for subnets that need external API access.

  • E. Incorrect.

    Incorrect: Using a single large subnet simplifies management but fails to provide the required isolation for compliance purposes.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam