ExamGecko
Ask Question

Google Professional Cloud Network Engineer Practice Test - Questions Answers, Page 15

Add to Whishlist

List of questions

Question 141

Report Export Collapse

Your organization is implementing a new security policy to control how firewall rules are applied to control flows between virtual machines (VMs). Using Google-recommended practices, you need to set up a firewall rule to enforce strict control of traffic between VM A and VM B. You must ensure that communications flow only from VM A to VM B within the VPC, and no other communication paths are allowed. No other firewall rules exist in the VPC. Which firewall rule should you configure to allow only this communication path?

Become a Premium Member for full access
  Unlock Premium Member

Question 142

Report Export Collapse

You have configured a service on Google Cloud that connects to an on-premises service via a Dedicated Interconnect. Users are reporting recent connectivity issues. You need to determine whether the traffic is being dropped because of firewall rules or a routing decision. What should you do?

Become a Premium Member for full access
  Unlock Premium Member

Question 143

Report Export Collapse

You are configuring a new HTTP application that will be exposed externally behind both IPv4 and IPv6virtual IP addresses, using ports 80, 8080, and 443. You will have backends in two regions: us-west1and us-east1. You want to serve the content with the lowest-possible latency while ensuring highavailability and autoscaling, and create native content-based rules using the HTTP hostname andrequest path. The IP addresses of the clients that connect to the load balancer need to be visible tothe backends. Which configuration should you use?

Become a Premium Member for full access
  Unlock Premium Member

Question 144

Report Export Collapse

You need to define an address plan for a future new Google Kubernetes Engine (GKE) cluster in your Virtual Private Cloud (VPC). This will be a VPC-native cluster, and the default Pod IP range allocation will be used. You must pre-provision all the needed VPC subnets and their respective IP address ranges before cluster creation. The cluster will initially have a single node, but it will be scaled to a maximum of three nodes if necessary. You want to allocate the minimum number of Pod IP addresses. Which subnet mask should you use for the Pod IP address range?

Become a Premium Member for full access
  Unlock Premium Member

Question 145

Report Export Collapse

You are responsible for designing a new connectivity solution for your organization's enterprise network to access and use Google Workspace. You have an existing Shared VPC with Compute Engine instances in us-west1. Currently, you access Google Workspace via your service provider's internet access. You want to set up a direct connection between your network and Google. What should you do?

Become a Premium Member for full access
  Unlock Premium Member

Question 146

Report Export Collapse

You suspect that one of the virtual machines (VMs) in your default Virtual Private Cloud (VPC) is under a denial-of-service attack. You need to analyze the incoming traffic for the VM to understand where the traffic is coming from. What should you do?

Become a Premium Member for full access
  Unlock Premium Member

Question 147

Report Export Collapse

You are responsible for configuring firewall policies for your company in Google Cloud. Your security team has a strict set of requirements that must be met to configure firewall rules.

Always allow Secure Shell (SSH) from your corporate IP address.

Restrict SSH access from all other IP addresses.

There are multiple projects and VPCs in your Google Cloud organization. You need to ensure that other VPC firewall rules cannot bypass the security team's requirements. What should you do?

Become a Premium Member for full access
  Unlock Premium Member

Question 148

Report Export Collapse

You are designing a new application that has backends internally exposed on port 800. The application will be exposed externally using both IPv4 and IPv6 via TCP on port 700. You want to ensure high availability for this application. What should you do?

Become a Premium Member for full access
  Unlock Premium Member

Question 149

Report Export Collapse

You work for a university that is migrating to Google Cloud.

These are the cloud requirements:

On-premises connectivity with 10 Gbps

Lowest latency access to the cloud

Centralized Networking Administration Team

New departments are asking for on-premises connectivity to their projects. You want to deploy the most cost-efficient interconnect solution for connecting the campus to Google Cloud.

What should you do?

Become a Premium Member for full access
  Unlock Premium Member

Question 150

Report Export Collapse

You have several microservices running in a private subnet in an existing Virtual Private Cloud (VPC).

You need to create additional serverless services that use Cloud Run and Cloud Functions to access the microservices. The network traffic volume between your serverless services and private microservices is low. However, each serverless service must be able to communicate with any of your microservices. You want to implement a solution that minimizes cost. What should you do?

Become a Premium Member for full access
  Unlock Premium Member
Total 215 questions
Go to page: of 22
Search

Related questions