Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 301 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 301

Select 3Google Cloud Platform

You are setting up a private GKE cluster in Google Cloud and need to ensure that the control plane endpoint is private while still allowing connectivity to the control plane. Additionally, you want to enable cluster nodes to access Google APIs without using public IP addresses. Which of the following steps should you take to meet these requirements?

  1. A

    Enable the private endpoint option for the cluster.

  2. B

    Disable the public endpoint for the control plane.

  3. C

    Configure a Cloud NAT gateway to provide internet access for the cluster nodes.

  4. D

    Enable Private Google Access on the subnet used by the cluster nodes.

  5. E

    Set up a VPN between the on-premises network and the private control plane endpoint.

Show answer and explanation

Correct answers: A, B, D

Explanation

To configure a private GKE cluster with a private control plane endpoint, you need to enable the private endpoint and disable the public endpoint. Additionally, enabling Private Google Access on the cluster's subnet ensures that the nodes can access Google APIs without public IP addresses. A Cloud NAT gateway is not required in this setup if Private Google Access is enabled, and a VPN is unnecessary unless there is an explicit on-premises connectivity requirement.

  • A. Correct.

    Enabling the private endpoint ensures that the control plane is accessible only through internal private IP addresses.

  • B. Correct.

    Disabling the public endpoint ensures that the control plane is not accessible over the public internet, aligning with the requirement to keep the control plane private.

  • C. Incorrect.

    Cloud NAT is used to provide internet access for private instances, but in this scenario, it is not required since Private Google Access enables nodes to communicate with Google APIs without public IPs.

  • D. Correct.

    Private Google Access allows cluster nodes to access Google APIs (such as Container Registry or Cloud Storage) using private IPs, which fulfills the requirement.

  • E. Incorrect.

    A VPN connection is not necessary for accessing the private control plane endpoint unless there is a specific requirement to connect from an on-premises network.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam