Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 300 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 300

Select 3Google Cloud Platform

You are configuring a private GKE cluster with a private control plane endpoint for a company that has strict security requirements. The cluster nodes and the control plane must communicate over private IPs only. Additionally, the cluster requires access to Google's APIs without exposing the nodes to the public internet. Which of the following steps must you take to meet these requirements?

  1. A

    Enable private endpoint for the control plane during cluster creation.

  2. B

    Enable private Google access on the subnet used by the cluster nodes.

  3. C

    Configure a NAT gateway for outgoing traffic from the cluster nodes.

  4. D

    Disable public endpoint access to the control plane.

  5. E

    Manually assign public IPs to cluster nodes for Google API access.

Show answer and explanation

Correct answers: A, B, D

Explanation

To configure a private GKE cluster with a private control plane endpoint, you need to enable the private endpoint for the control plane, enable private Google access on the subnet used by the cluster nodes, and disable public endpoint access to the control plane. These steps ensure that all communication is restricted to private IPs while still allowing access to Google's APIs. Configuring a NAT gateway is unnecessary because private Google access allows API communication directly over private IPs. Assigning public IPs would contradict the security requirements.

  • A. Correct.

    This is correct because enabling the private endpoint ensures that the cluster's control plane is only accessible via private IPs, meeting the security requirements.

  • B. Correct.

    This is correct because enabling private Google access allows the cluster nodes to reach Google's APIs (e.g., Container Registry) over private IPs without exposing them to the public internet.

  • C. Incorrect.

    This is incorrect because configuring a NAT gateway is not required for private clusters with private Google access enabled. The purpose of using private Google access is to avoid the need for NAT for API calls.

  • D. Correct.

    This is correct because disabling public endpoint access prevents the control plane from being accessible via the public internet, which aligns with the strict security requirements.

  • E. Incorrect.

    This is incorrect because assigning public IPs to cluster nodes violates the requirement to keep all communication over private IPs. It also defeats the purpose of using private Google access.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam