Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 661 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 661

Single answerGoogle Cloud Platform

You are tasked with setting up an HA VPN connection between your on-premises data center and your Google Cloud Virtual Private Cloud (VPC). After configuring the HA VPN gateway on Google Cloud with two interfaces, you notice that traffic fails over to the second tunnel only when the first tunnel is manually disabled. What is the most likely reason for this behavior?

  1. A

    You have not configured BGP for dynamic routing between the on-premises router and the HA VPN gateway.

  2. B

    The on-premises router is configured with static routes instead of dynamic routes.

  3. C

    The HA VPN gateway does not support failover between tunnels.

  4. D

    You must create a custom route in the VPC to force tunnel failover.

Show answer and explanation

Correct answer: B

Explanation

For HA VPN to provide automatic failover, both the Google Cloud HA VPN gateway and the on-premises router must be configured correctly. While the HA VPN gateway supports failover out-of-the-box, the on-premises router must use dynamic routing protocols like BGP to detect tunnel status changes and reroute traffic automatically. Static routes do not have this capability, requiring manual intervention to switch tunnels.

  • A. Incorrect.

    Incorrect. While BGP is recommended for dynamic routing, the absence of BGP does not prevent failover. Instead, it impacts route propagation and dynamic failover capabilities.

  • B. Correct.

    Correct. If the on-premises router is using static routes, it will not detect the failure of a tunnel automatically and will not route traffic through the second tunnel unless manual intervention occurs.

  • C. Incorrect.

    Incorrect. HA VPN is specifically designed to support failover between tunnels as long as the proper configurations are in place.

  • D. Incorrect.

    Incorrect. Custom routes in the VPC are not required for HA VPN failover. The issue lies with the on-premises router configuration.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam