Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 607 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 607

Select 2Google Cloud Platform

Your organization requires that all internal traffic flowing between two VPC networks in different regions is inspected for compliance with security policies. The inspection must occur in a centralized location. You are tasked with configuring this setup using Google Cloud. Which combination of configurations should you use to achieve this?

  1. A

    Deploy a Google Cloud firewall rule allowing traffic between the two VPC networks.

  2. B

    Set up a VPC Network Peering connection between the two VPC networks.

  3. C

    Configure a central hub VPC with a third-party network appliance for inspection.

  4. D

    Use a Cloud VPN or Cloud Interconnect to route traffic between the two VPC networks via the central hub.

  5. E

    Leverage Google Cloud's Private Service Connect to enforce inspection at a central location.

Show answer and explanation

Correct answers: C, D

Explanation

To implement centralized packet inspection between two VPCs in different regions, you should configure a hub-and-spoke topology. A central hub VPC with a third-party network appliance is used for inspection, while a routing mechanism like Cloud VPN or Cloud Interconnect ensures traffic flows through the hub. This setup enables compliance with security policies by inspecting all traffic between the VPCs.

  • A. Incorrect.

    This option does not address packet inspection. While firewall rules can control which traffic is allowed or denied, they do not provide deep packet inspection or compliance checks.

  • B. Incorrect.

    VPC Network Peering allows private connectivity between VPCs but does not provide a mechanism for centralized packet inspection.

  • C. Correct.

    A central hub VPC with a third-party network appliance is a common pattern for centralized packet inspection and can enforce compliance policies effectively.

  • D. Correct.

    Routing traffic via a central hub using Cloud VPN or Cloud Interconnect ensures that all traffic between the two VPCs flows through the inspection point, allowing the network appliance to analyze packets.

  • E. Incorrect.

    Private Service Connect is used for private communication between services and is not a suitable option for centralized traffic inspection.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam