Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 211 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 211

Select 3Google Cloud Platform

You are tasked with creating a private subnet in a Google Cloud VPC to enable internal communication for your application. The application also needs to access Google-managed services like BigQuery and Cloud Storage without exposing the subnet to the public internet. What steps should you take to properly configure the VPC resources?

  1. A

    Create a VPC network and a subnet with a custom IP range.

  2. B

    Enable Private Google Access on the subnet.

  3. C

    Create a firewall rule to allow ingress traffic from the public internet to the subnet.

  4. D

    Set up a Cloud NAT gateway for the subnet to enable outbound internet access.

  5. E

    Enable VPC Flow Logs for the subnet to monitor traffic.

Show answer and explanation

Correct answers: A, B, D

Explanation

To enable internal communication and access to Google-managed services while keeping the subnet private, you must first create a VPC network with a custom subnet. Enable Private Google Access on the subnet to allow access to Google APIs and services without public IPs. Finally, configure a Cloud NAT gateway to provide outbound internet access for the subnet while maintaining its private nature. Firewall rules and logging are important considerations but are not directly required for this scenario.

  • A. Correct.

    Creating a VPC network and custom subnet is a foundational step to set up the network resources required for your application.

  • B. Correct.

    Enabling Private Google Access allows instances in the private subnet to access Google APIs and services without needing a public IP address.

  • C. Incorrect.

    Creating a firewall rule to allow ingress traffic from the public internet is unnecessary and would expose the subnet, which contradicts the requirement of keeping it private.

  • D. Correct.

    A Cloud NAT gateway ensures that the private subnet can access the internet for outbound traffic (e.g., accessing Google APIs) without exposing it to inbound traffic from the public internet.

  • E. Incorrect.

    Enabling VPC Flow Logs is a good practice for monitoring traffic, but it is not directly required to achieve the goal of accessing Google-managed services from a private subnet.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam