Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 89 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 89

Single answerGoogle Cloud Platform

Your organization has a hybrid cloud setup, and you are tasked with connecting an on-premises environment to a Google Cloud VPC. The on-premises network uses private IP ranges defined by RFC 1918. You want to ensure that managed Google Cloud services such as Cloud SQL and Cloud Storage can still be accessed from the VPC without overlapping IP ranges causing connectivity issues. What should you do?

  1. A

    Use Private Google Access to allow VMs in the VPC to access Google-managed services without traversing the public internet.

  2. B

    Enable VPC peering between the on-premises network and the Google Cloud VPC to route traffic to managed services.

  3. C

    Configure Cloud NAT to allow egress traffic from the VPC to Google-managed services while keeping the private IP ranges intact.

  4. D

    Reserve a custom subnet in the VPC with non-RFC 1918 IP ranges to avoid conflicts with the on-premises network.

Show answer and explanation

Correct answer: A

Explanation

When connecting on-premises networks using RFC 1918 IP ranges to a Google Cloud VPC, enabling Private Google Access is the recommended method to allow instances in the VPC to access Google-managed services such as Cloud SQL and Cloud Storage. This avoids potential IP conflicts and ensures a secure connection without requiring public IP addresses. Other options like VPC peering or Cloud NAT are not designed for this use case.

  • A. Correct.

    Private Google Access allows VMs in a subnet with a private IP address to access Google-managed services such as Cloud Storage and Cloud SQL without requiring public IP addresses. This is the correct solution for this scenario.

  • B. Incorrect.

    VPC peering is used to connect two VPCs for private communication, but it is not applicable for connecting to managed Google services. This option does not address the problem.

  • C. Incorrect.

    Cloud NAT is used to provide internet access to instances without external IPs, but it does not solve the issue of accessing Google-managed services using RFC 1918 ranges.

  • D. Incorrect.

    Using non-RFC 1918 IP ranges can prevent conflicts, but it is not required to access managed Google services. Private Google Access is the simpler and more effective solution.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam