Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 611 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 611

Select 3Google Cloud Platform

You are tasked with setting up a next-generation firewall (NGFW) appliance in Google Cloud to inspect and route inter-VPC traffic between two VPCs: VPC-A and VPC-B. The NGFW is deployed as a multi-NIC VM with interfaces nic0 and nic1. nic0 is connected to VPC-A, and nic1 is connected to VPC-B. Which of the following steps are required to ensure inter-VPC traffic is routed through the NGFW for inspection?

  1. A

    Create a route in VPC-A with the next hop set to nic0's internal IP address.

  2. B

    Enable IP forwarding on the NGFW VM instance.

  3. C

    Create a route in VPC-B with the next hop set to nic1's internal IP address.

  4. D

    Enable VPC peering between VPC-A and VPC-B.

  5. E

    Configure the NGFW to forward traffic between nic0 and nic1.

Show answer and explanation

Correct answers: A, B, E

Explanation

Routing inter-VPC traffic through a next-generation firewall (NGFW) requires creating appropriate routes in the source VPC (VPC-A in this case) to direct traffic to the NGFW's network interface. Enabling IP forwarding on the NGFW is necessary to allow the instance to act as a transit device. Finally, the NGFW itself must be configured to forward traffic between its interfaces for inspection. VPC peering is not required in this scenario because the NGFW acts as the intermediary, and a route from VPC-B to nic1 is unnecessary because traffic routing back to VPC-A will already be handled through existing configurations.

  • A. Correct.

    Correct. A route in VPC-A is required so that traffic destined for VPC-B is sent to the NGFW's nic0 for inspection.

  • B. Correct.

    Correct. Enabling IP forwarding on the NGFW VM allows it to act as a transit device and forward traffic between its interfaces.

  • C. Incorrect.

    Incorrect. A route in VPC-B pointing to nic1's IP is not required because traffic from VPC-B to VPC-A will already be routed back to the NGFW based on existing routing configurations.

  • D. Incorrect.

    Incorrect. VPC peering is not required in this setup, as the NGFW serves as the intermediary for traffic between the VPCs.

  • E. Correct.

    Correct. The NGFW must be configured to forward traffic from one network interface to the other to inspect and route traffic between VPC-A and VPC-B.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam