Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 228 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 228

Select 2Google Cloud Platform

Your organization uses Compute Engine instances in a private subnet and needs these instances to access Google APIs and services like Cloud Storage and BigQuery without using public IP addresses. Which configuration steps should you take to ensure this setup works correctly?

  1. A

    Enable Private Google Access on the subnet where the Compute Engine instances reside.

  2. B

    Configure a Cloud NAT gateway for the subnet to allow outbound traffic to the internet.

  3. C

    Assign a public IP address to the Compute Engine instances.

  4. D

    Ensure the firewall rules allow egress traffic to 0.0.0.0/0 on ports 80 and 443.

  5. E

    Enable the 'Allow access to Google APIs' option in the Compute Engine instance's metadata.

Show answer and explanation

Correct answers: A, B

Explanation

To allow Compute Engine instances in a private subnet to access Google APIs without public IP addresses, you must enable Private Google Access on the subnet and configure a Cloud NAT gateway for outbound traffic. Private Google Access ensures traffic to Google APIs is routed internally, and the Cloud NAT gateway handles outbound traffic for instances without public IPs. Public IPs or overly permissive firewall rules are not required.

  • A. Correct.

    Correct: Enabling Private Google Access on the subnet allows instances without public IPs to connect to Google APIs and services.

  • B. Correct.

    Correct: Configuring a Cloud NAT gateway allows private instances to send outbound traffic to the internet, including Google APIs, without requiring public IPs.

  • C. Incorrect.

    Incorrect: Assigning a public IP address is not required for accessing Google APIs if Private Google Access is enabled.

  • D. Incorrect.

    Incorrect: While firewall rules can control traffic, a rule allowing 0.0.0.0/0 is unnecessary and overly permissive for this use case.

  • E. Incorrect.

    Incorrect: There is no such 'Allow access to Google APIs' option in the Compute Engine instance's metadata. This option does not exist.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam