Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 612 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 612

Select 4Google Cloud Platform

You are tasked with designing a Google Cloud solution to route and inspect inter-VPC traffic between two VPCs: VPC-A and VPC-B. For security purposes, a third VPC (VPC-Firewall) is hosting a next-generation firewall appliance on a multi-NIC VM. The firewall VM has one NIC attached to VPC-A and another NIC attached to VPC-B. What steps must you take to ensure the inter-VPC traffic is routed through the firewall for inspection?

  1. A

    Configure custom routes in VPC-A to forward traffic destined for VPC-B to the firewall VM's NIC in VPC-A.

  2. B

    Enable IP forwarding on the firewall VM.

  3. C

    Configure custom routes in VPC-B to forward traffic destined for VPC-A to the firewall VM's NIC in VPC-B.

  4. D

    Ensure the firewall VM has the 'Private Google Access' feature enabled.

  5. E

    Apply a firewall rule in VPC-A to allow traffic to the firewall VM's NIC.

Show answer and explanation

Correct answers: A, B, C, E

Explanation

To route and inspect inter-VPC traffic using a multi-NIC VM acting as a next-generation firewall, you need to configure custom routes in both VPCs to direct traffic to the respective NICs of the firewall VM. Additionally, IP forwarding must be enabled on the firewall VM to allow it to forward packets between its NICs. Finally, appropriate firewall rules must be applied to allow traffic to and from the firewall VM. The 'Private Google Access' feature is unrelated to inter-VPC traffic inspection and is not required.

  • A. Correct.

    Correct. Custom routes are required in VPC-A to direct traffic destined for VPC-B to the firewall VM's NIC in VPC-A. Without this, traffic will not pass through the firewall for inspection.

  • B. Correct.

    Correct. IP forwarding must be enabled on the firewall VM to allow it to forward traffic between its NICs. This is essential for routing traffic between VPCs through the firewall.

  • C. Correct.

    Correct. Custom routes are required in VPC-B to direct traffic destined for VPC-A to the firewall VM's NIC in VPC-B. This ensures return traffic also passes through the firewall for inspection.

  • D. Incorrect.

    Incorrect. 'Private Google Access' is not relevant to this scenario, as it is used to enable VMs without external IP addresses to access Google APIs and services. This does not affect inter-VPC traffic routing and inspection.

  • E. Correct.

    Correct. Firewall rules must be applied in VPC-A to allow traffic to the firewall VM's NIC. Without this rule, traffic will be blocked before reaching the firewall VM.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam