
[Jan-2022] Free Professional-Cloud-Network-Engineer Exam Questions Professional-Cloud-Network-Engineer Actual Free Exam Questions
Verified Professional-Cloud-Network-Engineer dumps and 80 unique questions
The benefit of obtaining the Google Professional Cloud Network Engineer Exam Certification
- Google Professional Cloud Network Engineer Certification is distinguished among competitors. Google Professional Cloud Network Engineer certification can give them an edge at that time easily when candidates appear for employment interview, employers are very fascinated to note one thing that differentiates the individual from all other candidates.
- Google Professional Cloud Network Engineer will be confident and stand different from others as their skills are more trained than non-certified professionals.
- Google Professional Cloud Network Engineer Certifications provide opportunities to get a job easily in which they are interested in instead of wasting years and ending without getting any experience.
- Google Professional Cloud Network Engineer certification has more useful and relevant networks that help them in setting career goals for themselves. Google Professional Cloud Network Engineer networks provide them with the correct career guidance than non certified generally are unable to get.
- Google Professional Cloud Network Engineer Certification provides practical experience to candidates from all the aspects to be a proficient worker in the organization.
- Google Professional Cloud Network Engineer Exam provide proven knowledge to use the tools to complete the task efficiently and cost effectively than the other non-certified professionals lack in doing so.
For more info visit:
CCIE to Google Cloud Network Engineer Google cloud network engineer practice exam Google Cloud documentation Google Cloud solutions Security & Identity Fundamentals
Topics of Google Professional Cloud Network Engineer Exam
Candidates must know the exam topics before they start of preparation. because it will really help them in hitting the core. Our Google Professional Cloud Network Engineer Dumps will include the following topics:
Network architectures, this individual ensures successful cloud implementations using the command line interface or the Google Cloud Platform Console.
1. Designing, planning, and prototyping a GCP network
Designing the overall network architecture
- SaaS, PaaS, and IaaS services
- Microsegmentation for security purposes (e.g., using metadata, tags)
- Container networking
- Options for high availability
- Hybrid connectivity (e.g., Google private access for hybrid connectivity)
- Optimizing for latency (e.g., MTU size, caches, CDN)
- Understanding how quotas are applied per project and per VPC
- Choosing the appropriate load balancing options
- Failover and disaster recovery strategy
- Meeting business requirements
- IAM and security
- DNS strategy (e.g., on-premises, Cloud DNS, GSLB)
Designing a Virtual Private Cloud (VPC). Considerations include:
- Firewall (e.g., service accountâÂÂbased, tag-based)
- Standalone or shared
- Multi-zone and multi-region
- CIDR range for subnets
- Routes
- IP addressing (e.g., static, ephemeral, private)
- Differences between Google Cloud Networking and other cloud platforms
- Multiple vs. single
- Peering
Designing a hybrid network. Considerations include:
- IPsec VPN
- Cloud Router
- Shared vs. standalone VPC interconnect access
- Using interconnect (e.g., dedicated vs. partner)
- Bandwidth
- Cross-organizational access
- Failover and disaster recovery strategy (e.g., building high availability with BGP using cloud router)
- Peering options (e.g., direct vs. carrier)
Designing a container IP addressing plan for Google Kubernetes Engine
2. Implementing a GCP Virtual Private Cloud (VPC)
Configuring VPCs. Considerations include:
- Creating a shared VPC and explaining how to share subnets with other projects
- Configuring GCP VPC resources (CIDR range, subnets, firewall rules, etc.)
- Configuring VPC flow logs
- Configuring VPC peering
- Configuring API access (private, public, NAT GW, proxy)
Configuring routing. Tasks include:
- Configuring internal static/dynamic routing
- Configuring NAT (e.g., Cloud NAT, instance-based NAT)
- Configuring routing policies using tags and priority
Configuring and maintaining Google Kubernetes Engine clusters. Considerations include:
- Private clusters
- Cluster network policy
- Adding authorized networks for cluster master access
- Clusters with shared VPC
- VPC-native clusters using alias IPs
Configuring and managing firewall rules. Considerations include:
- Firewall logs
- Target network tags and service accounts
- Ingress and egress rules
- Priority
- Network protocols
3. Configuring network services
Configuring load balancing. Considerations include:
- Capacity scaling
- HTTP(S) load balancer: including changing URL maps, backend groups, health checks, CDN, and SSL certs
- Firewall and security rules
- Network load balancer
- Creating backend services
- Internal load balancer
- TCP and SSL proxy load balancers
- Session affinity
Configuring Cloud CDN. Considerations include:
- Signed URLs
- Using cache keys
- Enabling and disabling Cloud CDN
- Cache invalidation
Configuring and maintaining Cloud DNS. Considerations include:
- Global serving with Anycast
- Migrating to Cloud DNS
- Internal DNS
- Cloud DNS
- DNS Security (DNSSEC)
- Integrating on-premises DNS with GCP
- Managing zones and records
Enabling other network services. Considerations include:
- Canary (A/B) releases
- Distributing backend instances using regional managed instance groups
- Health checks for your instance groups
- Enabling private API access
4. Implementing hybrid interconnectivity
Configuring interconnect. Considerations include:
- Bulk storage uploads
- Partner (e.g., layer 2 vs. layer 3 connectivity)
- Virtualizing using VLAN attachments
Configuring a site-to-site IPsec VPN (e.g., route-based, policy-based, dynamic or static routing).
Configuring Cloud Router for reliability.
5. Implementing network security
Configuring identity and access management (IAM). Tasks include:
- Defining custom IAM roles
- Viewing account IAM assignments
- Assigning IAM roles to accounts or Google Groups
- Using pre-defined IAM roles (e.g., network admin, network viewer, network user)
Configuring Cloud Armor policies. Considerations include:
- IP-based access control
Configuring third-party device insertion into VPC using multi-nic (NGFW)
Managing keys for SSH access
6. Managing and monitoring network operations
Logging and monitoring with Stackdriver or GCP Console
Managing and maintaining security. Considerations include:
- Diagnosing and resolving IAM issues (shared VPC, security/network admin)
- Firewalls (e.g., cloud-based, private)
Maintaining and troubleshooting connectivity issues. Considerations include:
- Managing and troubleshooting VPNs
- Troubleshooting Cloud Router BGP peering issues
- Monitoring ingress and egress traffic using flow logs
- Cross-connect handoff for interconnect
- Identifying traffic flow topology (e.g., load balancers, SSL offload, network endpoint groups)
- Draining and redirecting traffic flows
- Monitoring firewall logs
Monitoring, maintaining, and troubleshooting latency and traffic flow. Considerations include:
Network throughput and latency testing Routing issues Tracing traffic flow
7. Optimizing network resources
Optimizing traffic flow. Considerations include:
- Load balancer and CDN location
- Expanding subnet CIDR ranges in service
- Accommodating workload increases (e.g., autoscaling vs. manual scaling)
- Global vs. regional dynamic routing
Optimizing for cost and efficiency. Considerations include:
- Automation
- Cost optimization (Network Service Tiers, Cloud CDN, autoscaler [max instances])
- VPN vs. interconnect
- Bandwidth utilization (e.g., kernel sys tuning parameters)
NEW QUESTION 17
Your software team is developing an on-premises web application that requires direct connectivity to Compute Engine Instances in GCP using the RFC 1918 address space. You want to choose a connectivity solution from your on-premises environment to GCP, given these specifications:
* Your ISP is a Google Partner Interconnect provider.
* Your on-premises VPN device's internet uplink and downlink speeds are 10 Gbps.
* A test VPN connection between your on-premises gateway and GCP is performing at a maximum speed of
500 Mbps due to packet losses.
* Most of the data transfer will be from GCP to the on-premises environment.
* The application can burst up to 1.5 Gbps during peak transfers over the Interconnect.
* Cost and the complexity of the solution should be minimal.
How should you provision the connectivity solution?
- A. Create multiple VPN tunnels to account for the packet losses, and increase bandwidth using ECMP.
- B. Provision a Partner Interconnect through your ISP.
- C. Provision a Dedicated Interconnect instead of a VPN.
- D. Use network compression over your VPN to increase the amount of data you can send over your VPN.
Answer: A
NEW QUESTION 18
You need to enable Cloud CDN for all the objects inside a storage bucket. You want to ensure that all the objects in the storage bucket can be served by the CDN.
What should you do in the GCP Console?
- A. Create a new cloud storage bucket, and then enable Cloud CDN on it.
- B. Create a new SSL proxy load balancer, select the storage bucket as a backend, and then enable Cloud CDN on the backend.
- C. Create a new HTTP load balancer, select the storage bucket as a backend, enable Cloud CDN on the backend, and make sure each object inside the storage bucket is shared publicly.
- D. Create a new TCP load balancer, select the storage bucket as a backend, and then enable Cloud CDN on the backend.
Answer: A
NEW QUESTION 19
You are designing a shared VPC architecture. Your network and security team has strict controls over which routes are exposed between departments. Your Production and Staging departments can communicate with each other, but only via specific networks. You want to follow Google-recommended practices.
How should you design this topology?
- A. Create 2 shared VPCs within the shared VPC Host Project, and create a Cloud VPN/Cloud Router between them. Use Flexible Route Advertisement (FRA) to filter access between the specific networks.
- B. Create 1 VPC within the shared VPC Host Project, and share individual subnets with the Service Projects to filter access between the specific networks.
- C. Create 2 shared VPCs within the shared VPC Service Project, and create a Cloud VPN/Cloud Router between them. Use Flexible Route Advertisement (FRA) to filter access between the specific networks.
- D. Create 2 shared VPCs within the shared VPC Host Project, and enable VPC peering between them. Use firewall rules to filter access between the specific networks.
Answer: B
NEW QUESTION 20
You want to deploy a VPN Gateway to connect your on-premises network to GCP. You are using a non BGP- capable on-premises VPN device. You want to minimize downtime and operational overhead when your network grows. The device supports only IKEv2, and you want to follow Google-recommended practices.
What should you do?
- A. * Create a Cloud VPN instance.
* Create a route-based VPN tunnel.
* Configure the appropriate local and remote traffic selectors to match your local and remote networks.
* Configure the appropriate static routes. - B. * Create a Cloud VPN instance.
* Create a route-based VPN tunnel.
* Configure the appropriate local and remote traffic selectors to 0.0.0.0/0.
* Configure the appropriate static routes. - C. * Create a Cloud VPN instance.
* Create a policy-based VPN tunnel per subnet.
* Configure the appropriate local and remote traffic selectors to match your local and remote networks.
* Create the appropriate static routes. - D. * Create a Cloud VPN instance.
* Create a policy-based VPN tunnel.
* Configure the appropriate local and remote traffic selectors to match your local and remote networks.
* Configure the appropriate static routes.
Answer: B
Explanation:
Explanation/Reference: https://cloud.google.com/vpn/docs/concepts/choosing-networks-routing
NEW QUESTION 21
You want to configure load balancing for an internet-facing, standard voice-over-IP (VOIP) application.
Which type of load balancer should you use?
- A. HTTP(S) load balancer
- B. Internal TCP/UDP load balancer
- C. Network load balancer
- D. TCP/SSL proxy load balancer
Answer: C
NEW QUESTION 22
You want to establish a dedicated connection to Google that can access Cloud SQL via a public IP address and that does not require a third-party service provider.
Which connection type should you choose?
- A. Carrier Peering
- B. Partner Interconnect
- C. Direct Peering
- D. Dedicated Interconnect
Answer: C
Explanation:
Reference:
https://cloud.google.com/interconnect/docs/how-to/direct-peering
NEW QUESTION 23
You are adding steps to a working automation that uses a service account to authenticate. You need to drive the automation the ability to retrieve files from a Cloud Storage bucket. Your organization requires using the least privilege possible.
What should you do?
- A. Grant the compute.instanceAdmin to your user account.
- B. Grant the cloud-platform privilege to the service account for the Cloud Storage bucket.
- C. Grant the iam.serviceAccountUser to your user account.
- D. Grant the read-only privilege to the service account for the Cloud Storage bucket.
Answer: C
Explanation:
https://cloud.google.com/compute/docs/access/iam
NEW QUESTION 24
You want to deploy a VPN Gateway to connect your on-premises network to GCP. You are using a non BGP-capable on-premises VPN device. You want to minimize downtime and operational overhead when your network grows. The device supports only IKEv2, and you want to follow Google-recommended practices.
What should you do?
- A. Create a Cloud VPN instance.
Create a route-based VPN tunnel.
Configure the appropriate local and remote traffic selectors to match your local and remote networks.
Configure the appropriate static routes. - B. Create a Cloud VPN instance.
Create a route-based VPN tunnel.
Configure the appropriate local and remote traffic selectors to 0.0.0.0/0.
Configure the appropriate static routes. - C. Create a Cloud VPN instance.
Create a policy-based VPN tunnel.
Configure the appropriate local and remote traffic selectors to match your local and remote networks.
Configure the appropriate static routes. - D. Create a Cloud VPN instance.
Create a policy-based VPN tunnel per subnet.
Configure the appropriate local and remote traffic selectors to match your local and remote networks.
Create the appropriate static routes.
Answer: B
Explanation:
https://cloud.google.com/vpn/docs/concepts/choosing-networks-routing
NEW QUESTION 25
You have recently been put in charge of managing identity and access management for your organization. You have several projects and want to use scripting and automation wherever possible. You want to grant the editor role to a project member.
Which two methods can you use to accomplish this? (Choose two.)
- A. setIamPolicy() via REST API
- B. gcloud pubsub add-iam-policy-binding Sprojectname --member user:Susername --role roles/editor
- C. GetIamPolicy() via REST API
- D. Enter an email address in the Add members field, and select the desired role from the drop-down menu in the GCP Console.
- E. gcloud projects add-iam-policy-binding Sprojectname --member user:Susername --role roles/editor
Answer: D,E
NEW QUESTION 26
You are increasing your usage of Cloud VPN between on-premises and GCP, and you want to support more traffic than a single tunnel can handle. You want to increase the available bandwidth using Cloud VPN.
What should you do?
- A. Double the MTU on your on-premises VPN gateway from 1460 bytes to 2920 bytes.
- B. Create two VPN tunnels on the same Cloud VPN gateway that point to the same destination VPN gateway IP address.
- C. Add a second on-premises VPN gateway with a different public IP address. Create a second tunnel on the existing Cloud VPN gateway that forwards the same IP range, but points at the new on-premises gateway IP.
- D. Add a second Cloud VPN gateway in a different region than the existing VPN gateway. Create a new tunnel on the second Cloud VPN gateway that forwards the same IP range, but points to the existing on-premises VPN gateway IP address.
Answer: B
NEW QUESTION 27
You are trying to update firewall rules in a shared VPC for which you have been assigned only Network Admin permissions. You cannot modify the firewall rules. Your organization requires using the least privilege necessary.
Which level of permissions should you request?
- A. Shared VPC Admin privileges from the Organization Admin.
- B. Service Project Admin privileges from the Shared VPC Admin.
- C. Organization Admin privileges from the Organization Admin.
- D. Security Admin privileges from the Shared VPC Admin.
Answer: D
Explanation:
A Shared VPC Admin can define a Security Admin by granting an IAM member the Security Admin (compute.securityAdmin) role to the host project. Security Admins manage firewall rules and SSL certificates.
NEW QUESTION 28
You need to create a GKE cluster in an existing VPC that is accessible from on-premises. You must meet the following requirements:
* IP ranges for pods and services must be as small as possible.
* The nodes and the master must not be reachable from the internet.
* You must be able to use kubectl commands from on-premises subnets to manage the cluster.
How should you create the GKE cluster?
- A. * Create a VPC-native GKE cluster using user-managed IP ranges.
* Enable a GKE cluster network policy, set the pod and service ranges as /24.
* Set up a network proxy to access the master.
* Enable master authorized networks. - B. * Create a VPC-native GKE cluster using user-managed IP ranges.
* Enable privateEndpoint on the cluster master.
* Set the pod and service ranges as /24.
* Set up a network proxy to access the master.
* Enable master authorized networks. - C. * Create a VPC-native GKE cluster using GKE-managed IP ranges.
* Set the pod IP range as /21 and service IP range as /24.
* Set up a network proxy to access the master. - D. * Create a private cluster that uses VPC advanced routes.
* Set the pod and service ranges as /24.
* Set up a network proxy to access the master.
Answer: A
Explanation:
Explanation/Reference: https://cloud.google.com/kubernetes-engine/docs/how-to/alias-ips
NEW QUESTION 29
You need to define an address plan for a future new GKE cluster in your VPC. This will be a VPC native cluster, and the default Pod IP range allocation will be used. You must pre-provision all the needed VPC subnets and their respective IP address ranges before cluster creation. The cluster will initially have a single node, but it will be scaled to a maximum of three nodes if necessary. You want to allocate the minimum number of Pod IP addresses.
Which subnet mask should you use for the Pod IP address range?
- A. /22
- B. /25
- C. /21
- D. /23
Answer: B
Explanation:
Reference:
https://cloud.google.com/kubernetes-engine/docs/how-to/alias-ips
NEW QUESTION 30
You are creating an instance group and need to create a new health check for HTTP(s) load balancing.
Which two methods can you use to accomplish this? (Choose two.)
- A. Create a new legacy health check using the gcloud command line tool.
- B. Create a new health check, or select an existing one, when you complete the load balancer's backend configuration in the GCP Console.
- C. Create a new legacy health check using the Health checks section in the GCP Console.
- D. Create a new health check using the VPC Network section in the GCP Console.
- E. Create a new health check using the gcloud command line tool.
Answer: B,E
Explanation:
https://cloud.google.com/load-balancing/docs/health-checks#creating_and_modifying_health_checks
NEW QUESTION 31
You have a storage bucket that contains two objects. Cloud CDN is enabled on the bucket, and both objects have been successfully cached. Now you want to make sure that one of the two objects will not be cached anymore, and will always be served to the internet directly from the origin.
What should you do?
- A. Create a new storage bucket, and move the object you don't want to be checked anymore inside it. Then edit the bucket setting and enable the private attribute.
- B. Add a Cache-Control entry with value private to the metadata of the object you don't want to be cached anymore. Invalidate all the previously cached copies.
- C. Ensure that the object you don't want to be cached anymore is not shared publicly.
- D. Add an appropriate lifecycle rule on the storage bucket containing the two objects.
Answer: B
Explanation:
https://cloud.google.com/cdn/docs/invalidating-cached-content
NEW QUESTION 32
Your organization is deploying a single project for 3 separate departments. Two of these departments require network connectivity between each other, but the third department should remain in isolation. Your design should create separate network administrative domains between these departments. You want to minimize operational overhead.
How should you design the topology?
- A. Create 3 separate VPCs, and use VPC peering to establish connectivity between the two appropriate VPCs.
- B. Create a single project, and deploy specific firewall rules. Use network tags to isolate access between the departments.
- C. Create a Shared VPC Host Project and the respective Service Projects for each of the 3 separate departments.
- D. Create 3 separate VPCs, and use Cloud VPN to establish connectivity between the two appropriate VPCs.
Answer: C
Explanation:
Use Shared VPC to connect to a common VPC network. Resources in those projects can communicate with each other securely and efficiently across project boundaries using internal IPs. You can manage shared network resources, such as subnets, routes, and firewalls, from a central host project, enabling you to apply and enforce consistent network policies across the projects.
With Shared VPC and IAM controls, you can separate network administration from project administration.
This separation helps you implement the principle of least privilege. For example, a centralized network team can administer the network without having any permissions into the participating projects. Similarly, the project admins can manage their project resources without any permissions to manipulate the shared network.
https://cloud.google.com/docs/enterprise/best-practices-for-enterprise-organizations
NEW QUESTION 33
You need to ensure your personal SSH key works on every instance in your project. You want to accomplish this as efficiently as possible.
What should you do?
- A. Create a custom Google Compute Engine image with your public ssh key embedded.
- B. Use gcloud compute sshto automatically copy your public ssh key to the instance.
- C. Upload your public ssh key to each instance Metadata.
- D. Upload your public ssh key to the project Metadata.
Answer: D
Explanation:
Explanation/Reference: https://cloud.google.com/compute/docs/instances/adding-removing-ssh-keys
NEW QUESTION 34
You have a web application that is currently hosted in the us-central1 region. Users experience high latency when traveling in Asia. You've configured a network load balancer, but users have not experienced a performance improvement. You want to decrease the latency.
What should you do?
- A. Configure an HTTP load balancer, and direct the traffic to it.
- B. Configure a policy-based route rule to prioritize the traffic.
- C. Configure Dynamic Routing for the subnet hosting the application.
- D. Configure the TTL for the DNS zone to decrease the time between updates.
Answer: A
NEW QUESTION 35
You are using a 10-Gbps direct peering connection to Google together with the gsutil tool to upload files to Cloud Storage buckets from on-premises servers. The on-premises servers are 100 milliseconds away from the Google peering point. You notice that your uploads are not using the full 10-Gbps bandwidth available to you. You want to optimize the bandwidth utilization of the connection.
What should you do on your on-premises servers?
- A. Compress files using utilities like tar to reduce the size of data being sent.
- B. Remove the -m flag from the gsutil command to enable single-threaded transfers.
- C. Tune TCP parameters on the on-premises servers.
- D. Use the perfdiag parameter in your gsutil command to enable faster performance: gsutil perfdiag gs://[BUCKET NAME].
Answer: D
NEW QUESTION 36
You need to configure a static route to an on-premises resource behind a Cloud VPN gateway that is configured for policy-based routing using the gcloud command.
Which next hop should you choose?
- A. The IP address of the instance on the remote side of the VPN tunnel
- B. The IP address of the Cloud VPN gateway
- C. The name and region of the Cloud VPN tunnel
- D. The default internet gateway
Answer: C
Explanation:
Reference:
https://cloud.google.com/vpn/docs/how-to/creating-static-vpns
NEW QUESTION 37
You are increasing your usage of Cloud VPN between on-premises and GCP, and you want to support more traffic than a single tunnel can handle. You want to increase the available bandwidth using Cloud VPN.
What should you do?
- A. Double the MTU on your on-premises VPN gateway from 1460 bytes to 2920 bytes.
- B. Create two VPN tunnels on the same Cloud VPN gateway that point to the same destination VPN gateway IP address.
- C. Add a second Cloud VPN gateway in a different region than the existing VPN gateway.
Create a new tunnel on the second Cloud VPN gateway that forwards the same IP range, but points to the existing on-premises VPN gateway IP address. - D. Add a second on-premises VPN gateway with a different public IP address.
Create a second tunnel on the existing Cloud VPN gateway that forwards the same IP range, but points at the new on-premises gateway IP.
Answer: B
Explanation:
https://cloud.google.com/vpn/docs/concepts/classic-topologies
NEW QUESTION 38
Your company has a security team that manages firewalls and SSL certificates. It also has a networking team that manages the networking resources. The networking team needs to be able to read firewall rules, but should not be able to create, modify, or delete them.
How should you set up permissions for the networking team?
- A. Assign members of the networking team the compute.networkAdmin role.
- B. Assign members of the networking team a custom role with only the compute.networks.* and the compute.firewalls.list permissions.
- C. Assign members of the networking team the compute.networkUser role.
- D. Assign members of the networking team the compute.networkViewer role, and add the compute.networks.use permission.
Answer: A
Explanation:
https://cloud.google.com/compute/docs/access/iam
NEW QUESTION 39
You want to create a service in GCP using IPv6.
What should you do?
- A. Configure a TCP Proxy with the designated IPv6 address.
- B. Create the instance with the designated IPv6 address.
- C. Configure an internal load balancer with the designated IPv6 address.
- D. Configure a global load balancer with the designated IPv6 address.
Answer: D
Explanation:
https://cloud.google.com/load-balancing/docs/load-balancing-overview mentions to use global load balancer for IPv6 termination.
NEW QUESTION 40
......
Latest 100% Passing Guarantee - Brilliant Professional-Cloud-Network-Engineer Exam Questions PDF: https://www.testkingfree.com/Google/Professional-Cloud-Network-Engineer-practice-exam-dumps.html
Professional-Cloud-Network-Engineer Dumps for Pass Guaranteed - Pass Professional-Cloud-Network-Engineer Exam: https://drive.google.com/open?id=1wjyINy71vva1FrI5lMxhioWWA8DSG9Ep