Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 610 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 610

Select 3Google Cloud Platform

You are tasked with routing and inspecting inter-VPC traffic in your Google Cloud environment using a next-generation firewall appliance deployed on a multi-NIC VM. The environment has two VPCs: VPC-A and VPC-B. The goal is to ensure that all traffic between these VPCs is inspected by the firewall. Which of the following steps are required to achieve this setup?

  1. A

    Deploy the firewall appliance VM with at least two NICs, one for each VPC.

  2. B

    Set up custom static routes in each VPC to forward traffic to the next-hop IP of the firewall VM.

  3. C

    Enable VPC network peering between VPC-A and VPC-B to establish connectivity.

  4. D

    Configure the firewall appliance VM to forward traffic between its NICs.

  5. E

    Create custom firewall rules in each VPC to allow traffic between the subnets of VPC-A and VPC-B.

Show answer and explanation

Correct answers: A, B, D

Explanation

To inspect inter-VPC traffic using a multi-NIC VM hosting a next-generation firewall appliance, you need to deploy the appliance with at least two NICs (one for each VPC), configure custom static routes to forward traffic through the firewall, and ensure the VM is set up to forward traffic between its NICs. VPC peering is not required since the traffic is routed through the firewall, and custom firewall rules for inter-VPC traffic are unnecessary because the inspection and routing are handled by the firewall appliance.

  • A. Correct.

    Correct: A multi-NIC VM is required to connect to multiple VPCs, allowing the firewall appliance to inspect traffic between them.

  • B. Correct.

    Correct: Custom static routes are needed to direct traffic through the firewall VM for inspection.

  • C. Incorrect.

    Incorrect: VPC network peering is not required in this scenario because the firewall VM serves as the intermediary for traffic inspection between VPCs.

  • D. Correct.

    Correct: The firewall VM must be configured to correctly forward traffic between its NICs; otherwise, traffic will not flow between the VPCs.

  • E. Incorrect.

    Incorrect: Custom firewall rules for inter-VPC traffic are not directly relevant in this scenario because traffic inspection is managed by the firewall appliance VM.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam