Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 320 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 320

Select 3Google Cloud Platform

You are configuring a Compute Engine instance in a private subnet to access external APIs on the internet. You want to ensure that the instance does not expose its private IP address but uses the NAT gateway's IP address instead. You also need to restrict the instance to access only a specific range of external IP addresses. Which steps must you take to achieve this?

  1. A

    Configure a Cloud NAT gateway for the subnet and enable NAT for all instances in the subnet.

  2. B

    Set up an IP Masquerade policy to control the source NAT behavior and restrict traffic to the required range of external IP addresses.

  3. C

    Configure a firewall rule to allow egress traffic from the subnet to the specific range of external IP addresses.

  4. D

    Assign a public IP address to the instance so it can communicate directly with external APIs.

  5. E

    Enable Private Google Access on the subnet to allow the instance to access external APIs.

Show answer and explanation

Correct answers: A, B, C

Explanation

To allow a private Compute Engine instance to access external APIs while hiding its private IP, you need a Cloud NAT gateway for source NAT. An IP Masquerade policy should be used to enforce restrictions on the specific external IP ranges the instance can access. Additionally, a firewall rule must be created to allow egress traffic to those external IP ranges. Assigning a public IP or enabling Private Google Access is not relevant to the requirements of this scenario.

  • A. Correct.

    Correct: A Cloud NAT gateway ensures that private instances in a subnet can access the internet while hiding their private IP addresses behind the NAT gateway's IP address.

  • B. Correct.

    Correct: An IP Masquerade policy is used to define which traffic should be source NAT'd and can be configured to restrict access to specific external IP address ranges.

  • C. Correct.

    Correct: A firewall rule is required to explicitly allow egress traffic from the subnet to the specified range of external IP addresses. Without this, traffic will be blocked.

  • D. Incorrect.

    Incorrect: Assigning a public IP address to the instance would expose its identity directly to the internet, which goes against the requirements of the scenario.

  • E. Incorrect.

    Incorrect: Private Google Access allows instances in a private subnet to access Google APIs and services, but it does not facilitate access to general external APIs or affect NAT configuration.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam