Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 313 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 313

Select 3Google Cloud Platform

Your organization has deployed a microservices application on Google Kubernetes Engine (GKE) and wants to use Cloud Service Mesh to manage service-to-service communication. The security team requires all communication between services to be encrypted using mutual TLS (mTLS). Additionally, the operations team wants to monitor service health and gather telemetry data. Which steps should you take to meet these requirements?

  1. A

    Enable Anthos Service Mesh on your GKE cluster and configure automatic sidecar injection.

  2. B

    Manually deploy Envoy proxies to each pod in your cluster to handle mTLS encryption.

  3. C

    Configure a policy in Anthos Service Mesh to enforce mutual TLS for service-to-service communication.

  4. D

    Enable the collection of telemetry data by integrating Anthos Service Mesh with Cloud Monitoring and Cloud Trace.

  5. E

    Deploy a custom Certificate Authority to issue TLS certificates for your services.

Show answer and explanation

Correct answers: A, C, D

Explanation

To meet the requirements of secure communication and monitoring, you need to enable Anthos Service Mesh, enforce mTLS policies, and configure telemetry collection. Anthos Service Mesh automates sidecar injection and certificate management, eliminating the need for manual Envoy deployments or custom Certificate Authorities. Integrating with Cloud Monitoring and Cloud Trace ensures telemetry data is available for the operations team.

  • A. Correct.

    Correct. Enabling Anthos Service Mesh on your GKE cluster and configuring automatic sidecar injection deploys the necessary Envoy sidecars to manage mTLS, telemetry, and service traffic.

  • B. Incorrect.

    Incorrect. Manually deploying Envoy proxies is not necessary as Anthos Service Mesh handles sidecar injection automatically when configured correctly.

  • C. Correct.

    Correct. Configuring a policy in Anthos Service Mesh to enforce mTLS ensures that all service-to-service communication is encrypted with mutual TLS.

  • D. Correct.

    Correct. Anthos Service Mesh natively integrates with Cloud Monitoring and Cloud Trace to provide telemetry data for services running in the mesh.

  • E. Incorrect.

    Incorrect. Anthos Service Mesh includes a built-in mechanism for issuing and rotating certificates, so deploying a custom Certificate Authority is not required.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam