Google
PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #113
Your company's on-premises network is connected to a VPC using a Cloud VPN tunnel. You have a static route of 0.0.0.0/0 with the VPN tunnel as its next hop defined in the VPC. All internet bound traff
Sign in or unlock PROFESSIONAL-CLOUD-NETWORK-ENGINEER to reveal the answer and full explanation for question #113. The question stem and answer options stay visible for context.
Submitted by certguy· Apr 18, 2026Implementing a Google Cloud network
Question
Your company's on-premises network is connected to a VPC using a Cloud VPN tunnel. You have a static route of 0.0.0.0/0 with the VPN tunnel as its next hop defined in the VPC. All internet bound traffic currently passes through the on-premises network. You configured Cloud NAT to translate the primary IP addresses of Compute Engine instances in one region. Traffic from those instances will now reach the internet directly from their VPC and not from the on-premises network. Traffic from the virtual machines (VMs) is not translating addresses as expected. What should you do?
Options
- ALower the TCP Established Connection Idle Timeout for the NAT gateway.
- BAdd firewall rules that allow ingress and egress of the external NAT IP address, have a target tag
- CAdd a default static route to the VPC with the default internet gateway as the next hop, the
- DIncrease the default min-ports-per-vm setting for the Cloud NAT gateway.
Unlock PROFESSIONAL-CLOUD-NETWORK-ENGINEER to see the answer
You've previewed enough free PROFESSIONAL-CLOUD-NETWORK-ENGINEER questions. Unlock PROFESSIONAL-CLOUD-NETWORK-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Cloud NAT#VPC Routing#Default Route#Cloud VPN