Google Professional Cloud Network Engineer Question 646
Select 4Google Cloud PlatformYou are tasked with securing communication on an interconnect between your on-premises data center and Google Cloud. You want to enable and configure MACsec to provide encryption at Layer 2. Which of the following steps are required to successfully set up MACsec on Google Cloud's Dedicated Interconnect?
- A
Ensure that the interconnect router on-premises supports IEEE 802.1AE (MACsec).
- B
Enable MACsec on the Google Cloud side by contacting Google Cloud Support.
- C
Configure a Key Encryption Key (KEK) and MACsec Connectivity Association Key (CAK) on both ends of the interconnect.
- D
Use a Partner Interconnect instead of a Dedicated Interconnect to enable MACsec.
- E
Verify that your interconnect connection is running at 100 Gbps, as MACsec is only supported on 100 Gbps links.
Show answer and explanation
Correct answers: A, B, C, E
Explanation
To enable MACsec on a Dedicated Interconnect, you must ensure that both ends support the MACsec standard (IEEE 802.1AE), contact Google Cloud Support to enable it, configure the required encryption keys (KEK and CAK), and verify that the interconnect is running at 100 Gbps. Partner Interconnect does not support MACsec, so it cannot be used for this purpose.
- A. Correct.
Correct: MACsec requires that both ends of the interconnect support the IEEE 802.1AE standard. This step ensures compatibility and secure communication.
- B. Correct.
Correct: Enabling MACsec on Google Cloud requires contacting Google Cloud Support, as it is not enabled by default for Dedicated Interconnect.
- C. Correct.
Correct: Configuring a KEK and CAK is essential for establishing a secure MACsec connection and authenticating both ends of the communication.
- D. Incorrect.
Incorrect: Partner Interconnect does not support MACsec. Only Dedicated Interconnect supports MACsec encryption.
- E. Correct.
Correct: MACsec is only supported on 100 Gbps Dedicated Interconnect links, so ensuring this requirement is met is crucial.