Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 229 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 229

Select 3Google Cloud Platform

You are configuring a GCP Virtual Private Cloud (VPC) for an application that needs to access Google APIs and services such as Pub/Sub and Cloud Storage. The application is hosted on Compute Engine instances without external IP addresses. To enable API access while keeping the instances private, what steps should you take?

  1. A

    Enable Private Google Access on the subnet where the instances are hosted.

  2. B

    Configure a Cloud NAT gateway for the subnet where the instances are hosted.

  3. C

    Assign external IP addresses to the Compute Engine instances.

  4. D

    Route all traffic from the instances to the default internet gateway.

  5. E

    Ensure the necessary IAM roles are assigned for accessing the required Google APIs.

Show answer and explanation

Correct answers: A, B, E

Explanation

To allow private Compute Engine instances (without external IP addresses) to access Google APIs and services, you must enable Private Google Access on the subnet that hosts the instances. Additionally, a Cloud NAT gateway is required to allow these instances to establish outbound connections securely. Assigning external IP addresses is not necessary and violates the goal of keeping the instances private. Finally, appropriate IAM roles are needed to provide access to specific Google APIs and services.

  • A. Correct.

    Correct: Private Google Access must be enabled on the subnet to allow instances without external IP addresses to access Google APIs and services.

  • B. Correct.

    Correct: A Cloud NAT gateway is required for private instances to access the internet and Google APIs when external IP addresses are not used.

  • C. Incorrect.

    Incorrect: Assigning external IP addresses would expose the instances to the public internet, which violates the requirement to keep the instances private.

  • D. Incorrect.

    Incorrect: Routing traffic to the default internet gateway does not ensure secure and private access to Google APIs, and it is not required when Private Google Access and Cloud NAT are configured.

  • E. Correct.

    Correct: Proper IAM roles must be assigned to the service accounts used by the instances to ensure they can authenticate and access the required Google APIs.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam