Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 208 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 208

Select 3Google Cloud Platform

Your organization is deploying a multi-tier application in Google Cloud. You need to configure a Virtual Private Cloud (VPC) to ensure that the front-end, application, and database tiers are isolated while allowing secure communication between tiers. Additionally, you want to minimize the risk of misconfigurations and maintain the principle of least privilege. What steps should you take to configure the VPC?

  1. A

    Create separate subnets for each tier and use private IP addresses for internal communication.

  2. B

    Use firewall rules to explicitly allow traffic only between the required subnets and deny all other traffic by default.

  3. C

    Enable VPC Flow Logs to monitor network traffic and detect unauthorized access.

  4. D

    Use the default VPC and rely on its default configurations for subnetting and firewall rules.

  5. E

    Configure peering between multiple VPCs for each tier to ensure isolation.

Show answer and explanation

Correct answers: A, B, C

Explanation

To configure a secure and well-isolated VPC for a multi-tier application, it is important to use subnets for logical isolation of tiers, apply tightly controlled firewall rules for communication, and enable monitoring using VPC Flow Logs. The default VPC and its configurations are not suitable for production environments, and VPC peering is not necessary for tier isolation within a single VPC.

  • A. Correct.

    Correct: Creating separate subnets for each tier ensures logical isolation and allows you to manage access control at the subnet level while using private IP addresses for secure communication within the VPC.

  • B. Correct.

    Correct: Explicitly defining firewall rules to allow specific traffic between subnets while denying all other traffic follows the principle of least privilege and enhances security.

  • C. Correct.

    Correct: Enabling VPC Flow Logs helps monitor network activity and provides visibility into potential unauthorized access or misconfigurations.

  • D. Incorrect.

    Incorrect: The default VPC is not suitable for production use as it comes with broad subnetting and permissive firewall rules, which do not align with the principle of least privilege.

  • E. Incorrect.

    Incorrect: VPC peering is used to connect different VPCs, not to isolate tiers within a single VPC. Subnets are the appropriate mechanism for tier isolation within a VPC.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam