Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 50 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 50

Single answerGoogle Cloud Platform

Your company is deploying a new application that requires connectivity to a managed Google Cloud SQL instance from a virtual machine (VM) in a private subnet within a VPC. The company mandates that traffic between the VM and Cloud SQL instance must use private IPs only, and no traffic should traverse the public internet. Which solution should you implement to meet this requirement?

  1. A

    Use Private Service Connect to establish private connectivity between the VM and the Cloud SQL instance.

  2. B

    Enable private services access on the VPC and configure the Cloud SQL instance with a private IP.

  3. C

    Configure a Cloud NAT gateway to allow private connectivity to the Cloud SQL instance.

  4. D

    Use Serverless VPC Access to connect the VM to the Cloud SQL instance.

Show answer and explanation

Correct answer: B

Explanation

The correct solution to ensure private connectivity between a VM in a private subnet and a Cloud SQL instance is to enable private services access. Private services access allows Google-managed services, such as Cloud SQL, to use private IPs and ensures that traffic does not traverse the public internet. Other options, such as Private Service Connect and Serverless VPC Access, are designed for different use cases and are not applicable in this scenario.

  • A. Incorrect.

    Private Service Connect enables private connectivity to services such as third-party SaaS providers or Google APIs, but it is not used for connecting VMs to Google Cloud SQL instances. This is not the correct solution in this scenario.

  • B. Correct.

    Enabling private services access allows you to allocate a private IP range to Google-managed services, such as Cloud SQL. This ensures that traffic between the VM and the Cloud SQL instance remains private and does not traverse the public internet. This is the correct solution.

  • C. Incorrect.

    Cloud NAT is used to allow private instances in a VPC to access the internet, but it does not facilitate private connectivity to Google-managed services like Cloud SQL. This is not applicable in this scenario.

  • D. Incorrect.

    Serverless VPC Access is used to connect serverless environments, such as Cloud Run or App Engine, to a VPC. It is not relevant for connecting a VM to a Cloud SQL instance. This is not the correct solution.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam