Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 287 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 287

Select 3Google Cloud Platform

You are tasked with deploying a high-availability application on Google Kubernetes Engine (GKE) that requires private communication between pods and external systems hosted in your on-premises network. The application also requires a secure and scalable way to expose its services to users over the internet. Which of the following configurations should you implement to meet these requirements?

  1. A

    Configure a private cluster in GKE to ensure pod-to-pod communication remains isolated and secure.

  2. B

    Set up a VPN or Cloud Interconnect to establish private connectivity between GKE and the on-premises network.

  3. C

    Use a GKE Ingress to expose the application's services to the internet with HTTPS.

  4. D

    Enable workload identity to allow pods to securely authenticate with Google Cloud services without using static service account keys.

  5. E

    Disable IP masquerading for the cluster to reduce NAT usage and increase connectivity efficiency.

Show answer and explanation

Correct answers: A, B, C

Explanation

To meet the requirements in the scenario, you need a private GKE cluster to secure internal communication, a VPN or Cloud Interconnect for private connectivity to the on-premises network, and a GKE Ingress to securely expose the application to the internet with HTTPS. Workload identity and disabling IP masquerading are good practices in general but are not specific solutions for the problem described in this scenario.

  • A. Correct.

    Correct: A private cluster ensures that nodes and pods communicate securely within the VPC without being exposed to the public internet, which is essential for high-security requirements.

  • B. Correct.

    Correct: A VPN or Cloud Interconnect is necessary to establish private communication between the GKE cluster and the on-premises network.

  • C. Correct.

    Correct: GKE Ingress provides a scalable and secure way to expose your application’s services to the internet, and it supports HTTPS for secure communication.

  • D. Incorrect.

    Incorrect: While enabling workload identity is a best practice for secure authentication of pods with Google Cloud services, it is not directly related to the requirements in this scenario (private on-premises communication and internet exposure).

  • E. Incorrect.

    Incorrect: Disabling IP masquerading is useful for optimizing connectivity in certain scenarios, but it is not required for achieving the goals outlined in this question.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam