Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 598 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 598

Select 3Google Cloud Platform

Your organization has deployed a private GKE cluster in Google Cloud. The cluster nodes do not have external IP addresses and need to pull container images from a public container registry. You have been asked to configure a solution that allows the nodes to access the internet securely without exposing them directly. Which of the following steps are required to configure Private NAT for this use case?

  1. A

    Create a Cloud NAT gateway and associate it with the VPC network used by the GKE cluster.

  2. B

    Configure a custom route in the VPC network to direct all egress traffic from the cluster nodes to the Cloud NAT gateway.

  3. C

    Enable Private Google Access in the subnet hosting the GKE cluster nodes.

  4. D

    Assign external IP addresses to the cluster nodes to enable internet connectivity.

  5. E

    Configure the Cloud NAT gateway to use manual IP address allocation with reserved static external IPs.

Show answer and explanation

Correct answers: A, C, E

Explanation

To allow private GKE cluster nodes to securely access the internet, a Cloud NAT gateway must be configured and associated with the VPC. In addition, enabling Private Google Access ensures that the nodes can connect to Google APIs such as the container registry. Using manual IP address allocation for the Cloud NAT gateway provides greater control over the external IPs used for egress traffic.

  • A. Correct.

    Correct: Cloud NAT provides a secure way for private resources, such as GKE cluster nodes without external IPs, to access the internet. Associating it with the VPC network ensures the NAT gateway can handle the traffic.

  • B. Incorrect.

    Incorrect: Custom routes are not required when using Cloud NAT. Cloud NAT automatically handles routing for eligible resources in the subnet.

  • C. Correct.

    Correct: Enabling Private Google Access allows the GKE cluster nodes to access Google APIs and services from a private IP address, which is required for pulling container images from a public container registry.

  • D. Incorrect.

    Incorrect: Assigning external IP addresses to the cluster nodes would expose them to the internet, which is against the requirement of keeping them private.

  • E. Correct.

    Correct: Configuring the Cloud NAT gateway with manual IP address allocation ensures predictable and consistent external IP addresses for outbound traffic, which may be required for compliance or logging purposes.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam