Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 42 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 42

Select 3Google Cloud Platform

You are designing a secure network architecture for a new application on Google Cloud. The application is composed of multiple microservices running in Google Kubernetes Engine (GKE). The security team has requested that you implement network micro-segmentation to control traffic between the microservices based on metadata and service identities. Which actions should you take to achieve this?

  1. A

    Use Kubernetes Network Policies to define ingress and egress rules for each microservice.

  2. B

    Leverage Identity and Access Management (IAM) roles to restrict communication between microservices.

  3. C

    Apply secure tags to microservices and use firewall rules to control traffic based on those tags.

  4. D

    Use workload identity and service accounts to authenticate and authorize traffic between microservices.

  5. E

    Configure Cloud NAT to enforce micro-segmentation between microservices.

Show answer and explanation

Correct answers: A, C, D

Explanation

To implement micro-segmentation in a GKE environment, you should use Kubernetes Network Policies to restrict traffic between microservices at the pod level. Additionally, secure tags and firewall rules can help enforce segmentation at the network level. Workload identity and service accounts ensure secure authentication and authorization, which is crucial for micro-segmentation. IAM roles and Cloud NAT do not directly address the requirements of network micro-segmentation.

  • A. Correct.

    Kubernetes Network Policies are essential for implementing network micro-segmentation at the pod level in GKE. They allow you to define ingress and egress traffic rules based on labels, which align with micro-segmentation goals.

  • B. Incorrect.

    IAM roles are not designed for network micro-segmentation. They are primarily used to control access to Google Cloud resources rather than managing traffic between microservices.

  • C. Correct.

    Secure tags can be applied to resources, and you can use VPC firewall rules to enforce network policies based on those tags, which supports micro-segmentation.

  • D. Correct.

    Workload identity and service accounts ensure authentication and authorization between microservices, which is a critical part of micro-segmentation for secure communication.

  • E. Incorrect.

    Cloud NAT is used for providing internet access to private instances and does not enforce micro-segmentation or control traffic between microservices.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam