Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 777 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 777

Single answerGoogle Cloud Platform

You are designing a network architecture for a new application in Google Cloud. The application runs in multiple regions and requires isolated environments for development, testing, and production. Each environment will have its resources contained within separate projects. You want to ensure that communication between these environments is controlled and project-scoped. Which networking approach should you use?

  1. A

    Use Shared VPC to connect all the projects and create firewall rules to restrict communication between environments.

  2. B

    Use VPC Network Peering to connect the projects and implement firewall rules to control communication between environments.

  3. C

    Use separate VPCs for each project and rely on IAM policies to control communication between environments.

  4. D

    Use Cloud VPN to connect the projects and manage communication through routing and firewall rules.

Show answer and explanation

Correct answer: B

Explanation

VPC Network Peering is the ideal solution in this scenario because it allows you to connect VPCs from different projects while maintaining project-scoped isolation. This ensures that each environment (development, testing, production) is contained within its own project and VPC, and communication between them can be controlled through specific configurations such as firewall rules.

  • A. Incorrect.

    Incorrect: Shared VPC allows multiple projects to share a single VPC network, but it is not project-scoped, as all projects share the same network resources. This approach does not provide the required isolation between environments.

  • B. Correct.

    Correct: VPC Network Peering is project-scoped, meaning resources are isolated within their respective VPCs. It allows controlled communication between environments while keeping resources separated at the project level.

  • C. Incorrect.

    Incorrect: Relying solely on IAM policies to control communication is insufficient for network-level isolation. Separate VPCs alone do not provide connectivity between projects without additional configuration.

  • D. Incorrect.

    Incorrect: Cloud VPN connects on-premises networks to Google Cloud or between Google Cloud networks, but it's not an efficient or scalable solution for communication between multiple Google Cloud projects in this scenario.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam