PROFESSIONAL-CLOUD-NETWORK-ENGINEER Exam Questions
262 real PROFESSIONAL-CLOUD-NETWORK-ENGINEER exam questions with expert-verified answers and explanations. Page 1 of 6.
- Question #1Configuring network services
Your company's web server administrator is migrating on-premises backend servers for an application to GCP. Libraries and configurations differ significantly across these backend s...
Network Load BalancerTarget PoolLift-and-shiftBackend Instances - Question #2Configuring network services
You decide to set up Cloud NAT. After completing the configuration, you find that one of your instances is not using the Cloud NAT for outbound NAT. What is the most likely cause o...
Cloud NATOutbound connectivityExternal IP addressesNetwork troubleshooting - Question #3Designing, planning, and prototyping a Google Cloud network
You want to set up two Cloud Routers so that one has an active Border Gateway Protocol (BGP) session, and the other one acts as a standby. Which BGP attribute should you use on you...
BGPMulti-exit Discriminator (MED)Hybrid ConnectivityActive/Standby - Question #4Designing, planning, and prototyping a Google Cloud network
You are increasing your usage of Cloud VPN between on-premises and GCP, and you want to support more traffic than a single tunnel can handle. You want to increase the available ban...
Cloud VPNHybrid ConnectivityNetwork ScalabilityVPN Gateway - Question #5Configuring network services
You are disabling DNSSEC for one of your Cloud DNS-managed zones. You removed the DS records from your zone file, waited for them to expire from the cache, and disabled DNSSEC for...
DNSSECCloud DNSDomain RegistrarDNS Resolution - Question #6Implementing network security
You have an application hosted on a Compute Engine virtual machine instance that cannot communicate with a resource outside of its subnet. When you review the flow and firewall log...
VPC Firewall RulesFirewall LoggingNetwork TroubleshootingImplicit Deny - Question #7Configuring network services
You have configured Cloud CDN using HTTP(S) load balancing as the origin for cacheable content. Compression is configured on the web servers, but responses served by Cloud CDN are...
Cloud CDNHTTP CompressionProxy BehaviorTroubleshooting - Question #8Configuring network services
You have a web application that is currently hosted in the us-central1 region. Users experience high latency when traveling in Asia. You've configured a network load balancer, but...
Load BalancingGlobal HTTP(S) Load BalancerLatency ReductionNetwork Performance - Question #9Configuring network services
You have an application running on Compute Engine that uses BigQuery to generate some results that are stored in Cloud Storage. You want to ensure that none of the application inst...
Private Google AccessCloud NATPrivate ConnectivityCompute Engine Networking - Question #10Designing, planning, and prototyping a Google Cloud network
You are designing a shared VPC architecture. Your network and security team has strict controls over which routes are exposed between departments. Your Production and Staging depar...
Shared VPCNetwork DesignSubnet SharingNetwork Isolation - Question #11Implementing network security
You are adding steps to a working automation that uses a service account to authenticate. You need to drive the automation the ability to retrieve files from a Cloud Storage bucket...
IAMService AccountsCloud StorageLeast Privilege - Question #12Implementing a Google Cloud network
You converted an auto mode VPC network to custom mode. Since the conversion, some of your Cloud Deployment Manager templates are no longer working. You want to resolve the problem....
VPC NetworksCustom Mode VPCDeployment ManagerSubnets - Question #13Implementing network security
You have recently been put in charge of managing identity and access management for your organization. You have several projects and want to use scripting and automation wherever p...
IAMgcloud CLIREST APIAutomation - Question #14Configuring network services
You are using a 10-Gbps direct peering connection to Google together with the gsutil tool to upload files to Cloud Storage buckets from on-premises servers. The on-premises servers...
Network PerformanceTCP OptimizationCloud Storage Uploads - Question #15Designing, planning, and prototyping a Google Cloud network
You work for a multinational enterprise that is moving to GCP. These are the cloud requirements: - An on-premises data center located in the United States in Oregon and New York wi...
Shared VPCNetwork SecurityVPC DesignInline Appliance - Question #16Designing, planning, and prototyping a Google Cloud network
You are designing a Google Kubernetes Engine (GKE) cluster for your organization. The current cluster size is expected to host 10 nodes, with 20 Pods per node and 150 services. Bec...
GKE NetworkingVPC-nativeIP Address ManagementNetwork Design - Question #17Designing, planning, and prototyping a Google Cloud network
Your company has recently expanded their EMEA-based operations into APAC. Globally distributed users report that their SMTP and IMAP services are slow. Your company requires end-to...
TCP Proxy Load BalancerGlobal Load BalancingSSL/TLS TerminationApplication Protocols (SMTP/IMAP) - Question #18Designing, planning, and prototyping a Google Cloud network
Your company is working with a partner to provide a solution for a customer. Both your company and the partner organization are using GCP. There are applications in the partner's n...
VPC ConnectivityCross-organization NetworkingVPC PeeringCloud VPN - Question #19Configuring network services
You have a storage bucket that contains the following objects: - folder-a/image-a-1.jpg - folder-a/image-a-2.jpg - folder-b/image-b-1.jpg - folder-b/image-b-2.jpg Cloud CDN is enab...
Cloud CDNCache InvalidationGoogle Cloud Storage - Question #20Implementing network security
Your company is running out of network capacity to run a critical application in the on-premises data center. You want to migrate the application to GCP. You also want to ensure th...
Network MonitoringNetwork SecurityVPC Flow LogsFirewall Logs - Question #21Implementing network security
You want to apply a new Cloud Armor policy to an application that is deployed in Google Kubernetes Engine (GKE). You want to find out which target to use for your Cloud Armor polic...
Cloud ArmorGKE IngressNetwork SecurityLoad Balancing - Question #22Designing, planning, and prototyping a Google Cloud network
You need to establish network connectivity between three Virtual Private Cloud networks, Sales, Marketing, and Finance, so that users can access resources in all three VPCs. You co...
VPC PeeringNetwork ConnectivityNon-transitive PeeringFull Mesh - Question #23Designing, planning, and prototyping a Google Cloud network
You create multiple Compute Engine virtual machine instances to be used at TFTP servers. Which type of load balancer should you use?
Google Cloud Load BalancersNetwork Load BalancerUDP ProtocolCompute Engine - Question #24Designing, planning, and prototyping a Google Cloud network
You want to configure load balancing for an internet-facing, standard voice-over-IP (VOIP) application. Which type of load balancer should you use?
Load BalancingExternal Load BalancersNetwork Load BalancerUDP Traffic - Question #25Configuring network services
You want to configure a NAT to perform address translation between your on-premises network blocks and GCP. Which NAT solution should you use?
NATiptablesHybrid ConnectivityVM as NAT Gateway - Question #26Implementing network security
You need to ensure your personal SSH key works on every instance in your project. You want to accomplish this as efficiently as possible. What should you do?
SSH Key ManagementCompute EngineProject MetadataInstance Access - Question #27Implementing network security
In order to provide subnet level isolation, you want to force instance-A in one subnet to route through a security appliance, called instance-B, in another subnet. What should you...
VPC RoutingCustom Static RoutesNetwork AppliancesNext-hop IP - Question #28Implementing network security
You create a Google Kubernetes Engine private cluster and want to use kubectl to get the status of the pods. In one of your instances you notice the master is not responding, even...
GKE Private ClustersMaster Authorized Networkskubectl connectivityNetwork Access Control - Question #29Implementing network security
Your company has a security team that manages firewalls and SSL certificates. It also has a networking team that manages the networking resources. The networking team needs to be a...
IAMRolesNetwork SecurityFirewall Rules - Question #30Configuring network services
Your organization requires that metrics from all applications be retained for 5 years for future analysis in possible legal proceedings. Which approach should you use?
Cloud MonitoringData RetentionGoogle Cloud StorageCompliance - Question #31Implementing a Google Cloud network
A lead engineer wrote a custom tool that deploys virtual machines in the legacy data center. He wants to migrate the custom tool to the new cloud environment. You want to advocate...
Deployment ManagerInfrastructure as CodeCloud MigrationBusiness Risks - Question #32Implementing network security
The security team has disabled external SSH access into production virtual machines in GCP. The operations team needs to remotely manage the VMs and other resources. What can they...
Google Cloud ShellRemote VM managementSecure accessNetwork security policies - Question #33Implementing a Google Cloud network
You have created several preemptible Linux virtual machine instances using Google Compute Engine. You want to properly shut down your application before the virtual machines are pr...
Preemptible VMsVM Lifecycle ManagementShutdown ScriptsMetadata - Question #34Implementing a Google Cloud network
A database virtual machine on Google Compute Engine has an ext4-formatted persistent disk for data files. The database is about to run out of storage space How can you remediate th...
Compute EnginePersistent DiskStorage ManagementDowntime Minimization - Question #35Designing, planning, and prototyping a Google Cloud network
Your company has launched a mobile application that uploads pictures to google cloud storage bucket. The application was successfully uploading the pictures to google cloud storage...
Cloud StorageAPI Error HandlingRate LimitingExponential Backoff - Question #36Designing, planning, and prototyping a Google Cloud network
You work for one of the biggest digital media company in USA .The company management has decided to move 90 TB of backups and archival data to Google Cloud. They are looking for lo...
Data MigrationCloud Storage ClassesArchival StorageDisaster Recovery - Question #37Configuring network services
You have setup a shared VPC and you have created three projects; Host Project, Service Project-1 and Service Project-2. You have created two subnets, subnet-1 in us-west1 and subne...
Shared VPCIAMPermissionsNetworking - Question #38Designing, planning, and prototyping a Google Cloud network
You have a data workflow which consists of data ingestion layer, data transformation layer, data analytics layer and data storage layer. You are looking for a service that would ea...
Workflow OrchestrationCloud ComposerData PipelinesManaged Services - Question #39Implementing network security
You need to restrict access to your Google Cloud load-balanced application so that only specific IP addresses can connect. What should you do?
Firewall RulesNetwork TagsAccess ControlNetwork Security - Question #40Designing, planning, and prototyping a Google Cloud network
Your end users are located in close proximity to us-east1 and europe-west1. Their workloads need to communicate with each other. You want to minimize cost and increase network effi...
VPC designMulti-region networkingNetwork efficiencyCost optimization - Question #41Designing, planning, and prototyping a Google Cloud network
Your organization is deploying a single project for 3 separate departments. Two of these departments require network connectivity between each other, but the third department shoul...
VPC ArchitectureVPC PeeringNetwork IsolationAdministrative Domains - Question #42Configuring network services
You are migrating to Cloud DNS and want to import your BIND zone file. Which command should you use?
Cloud DNSgcloud CLIDNS migrationBIND zone file - Question #43Designing, planning, and prototyping a Google Cloud network
You created a VPC network named Retail in auto mode. You want to create a VPC network named Distribution and peer it with the Retail VPC. How should you configure the Distribution...
VPC NetworkVPC PeeringAuto Mode VPCCustom Mode VPC - Question #44Implementing network security
You are using a third-party next-generation firewall to inspect traffic. You created a custom route of 0.0.0.0/0 to route egress traffic to the firewall. You want to allow your VPC...
Private Google AccessCustom RoutesEgress RoutingGoogle APIs Connectivity - Question #45Implementing network security
You have installed Apache Tomcat 8.X on a compute engine in google cloud on port 8085 and you have also installed Jenkins on the same machine on a custom port. You have created a f...
Firewall RulesCompute EngineNetwork SecurityNetwork Tags - Question #46Configuring network services
You are a admin at XYZ organization. Few of your team members need to use BigQuery Data Transfer Service for Amazon S3 . They want to automatically schedule and manage recurring lo...
BigQuery Data Transfer ServiceIAM PermissionsBigQueryData Ingestion - Question #47Implementing network security
Datachamps is an organization resource and it has many projects under it .The company uses BigQuery for data analysis. They want a user named admin-bigquery to be the admin for all...
BigQuery IAMIAM RolesService AccountsLeast Privilege - Question #48Designing, planning, and prototyping a Google Cloud network
You work for a organization called cloudtech5 . Your organization has decided to implement continuous integration and delivery (CI/CD) pipeline on Google Cloud Platform using only...
CI/CDGitOpsGoogle Kubernetes EngineManaged Services - Question #49Configuring network services
You have deployed a new internal application that provides HTTP and TFTP services to on- premises hosts. You want to be able to distribute traffic across multiple Compute Engine in...
Load BalancingSession AffinityMulti-protocol TrafficCompute Engine - Question #50Implementing network security
You created a new VPC network named Dev with a single subnet. You added a firewall rule for the network Dev to allow HTTP traffic only and enabled logging. When you try to log in t...
Firewall RulesLoggingNetwork SecurityTroubleshooting