Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 574 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 574

Select 2Google Cloud Platform

Your organization uses Google Cloud to host its applications and wants to configure and secure internet egress traffic from a Virtual Private Cloud (VPC). The requirements include allowing specific external APIs, blocking access to certain external IP ranges, and ensuring all traffic flows through a centralized inspection point. Which combination of configurations would best meet these requirements?

  1. A

    Use a Cloud NAT gateway to manage egress traffic and apply firewall rules to block specific external IP ranges.

  2. B

    Deploy a VPC Service Controls perimeter to restrict egress traffic to specific external APIs.

  3. C

    Configure a Private Google Access policy for the subnet to ensure access to external APIs is secured.

  4. D

    Set up a custom route directing all egress traffic through a third-party virtual appliance for inspection.

  5. E

    Use a Google Cloud Armor security policy to block egress traffic to specific external IP ranges.

Show answer and explanation

Correct answers: A, D

Explanation

To meet the requirements of securing and configuring egress internet traffic, a combination of using a Cloud NAT gateway with firewall rules and routing traffic through a third-party virtual appliance for inspection addresses both the need to block specific IP ranges and enforce centralized inspection. Other options either do not apply to egress traffic or do not meet all the stated requirements.

  • A. Correct.

    Using a Cloud NAT gateway allows you to manage egress traffic for private instances, and applying firewall rules can block specific external IP ranges. This directly addresses the requirement of blocking access to certain external IP ranges.

  • B. Incorrect.

    VPC Service Controls are designed to restrict access to sensitive data and APIs within Google services, not to control general internet egress traffic.

  • C. Incorrect.

    Private Google Access is used to allow private instances to access Google services, but it does not provide the ability to filter traffic based on external IP ranges or enforce centralized inspection.

  • D. Correct.

    Setting up a custom route to direct traffic through a third-party virtual appliance enables centralized traffic inspection and helps meet the requirement of inspecting all egress traffic.

  • E. Incorrect.

    Google Cloud Armor is used to manage and secure incoming traffic to Google Cloud resources, not to block or secure outbound egress traffic.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam