Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 571 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 571

Select 3Google Cloud Platform

Your organization uses a Google Cloud Virtual Private Cloud (VPC) and requires internet egress traffic to be routed through a third-party firewall for inspection and logging. Additionally, the security team mandates that only approved services and destinations should be accessible through this egress path. Which steps should you take to achieve this requirement?

  1. A

    Configure a Cloud NAT gateway for the VPC subnet to handle internet egress traffic.

  2. B

    Create a custom static route with the next hop set to a Cloud VPN or a Cloud Interconnect connecting to the third-party firewall.

  3. C

    Use VPC Firewall Rules to restrict egress traffic to only approved destinations and services.

  4. D

    Deploy a Private Google Access configuration to ensure traffic to Google APIs remains private.

  5. E

    Leverage a route-based VPN for traffic redirection to the third-party firewall.

  6. F

    Enable a Google Cloud Armor policy to restrict egress traffic based on approved destinations.

Show answer and explanation

Correct answers: B, C, E

Explanation

To route internet egress traffic through a third-party firewall and restrict access to approved destinations, you must create a custom route to redirect traffic via a Cloud VPN or Cloud Interconnect connected to the firewall. Additionally, VPC Firewall Rules are necessary to enforce restrictions on egress traffic based on approved destinations and services. A route-based VPN is a suitable method to achieve traffic redirection. Other options like Cloud NAT, Private Google Access, or Google Cloud Armor do not fulfill the specific requirements of traffic routing and restriction in this scenario.

  • A. Incorrect.

    Cloud NAT is used to provide internet access for private VM instances, but it does not allow for traffic inspection or routing through a third-party firewall.

  • B. Correct.

    Creating a custom static route with a next hop to a Cloud VPN or Cloud Interconnect is a valid way to redirect traffic to a third-party firewall for inspection.

  • C. Correct.

    VPC Firewall Rules can be used to restrict egress traffic to specific destinations and services, aligning with the security team's requirements for approved access.

  • D. Incorrect.

    Private Google Access is used to allow private VMs to access Google APIs without using external IP addresses. It is not relevant to routing traffic through a third-party firewall or restricting egress traffic.

  • E. Correct.

    Using a route-based VPN is a valid approach to redirect egress traffic to a third-party firewall for inspection.

  • F. Incorrect.

    Google Cloud Armor is used for protecting applications and services from external threats. It does not manage or restrict egress traffic from a VPC.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam