Google
PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #118
Your organization uses a hub-and-spoke architecture with critical Compute Engine instances in your Virtual Private Clouds (VPCs). You are responsible for the design of Cloud DNS in Google Cloud. You…
The correct answer is A. Configure a private DNS zone in the hub VPC, and configure DNS forwarding to the on-premises. https://cloud.google.com/dns/docs/best-practices#hybrid-architecture-using-hub-vpc-network- connected-to-spoke-vpc-networks
Submitted by wei.xz· Apr 18, 2026Designing, planning, and prototyping a Google Cloud network
Question
Your organization uses a hub-and-spoke architecture with critical Compute Engine instances in your Virtual Private Clouds (VPCs). You are responsible for the design of Cloud DNS in Google Cloud. You need to be able to resolve Cloud DNS private zones from your on-premises data center and enable on-premises name resolution from your hub-and-spoke VPC design. What should you do?
Options
- AConfigure a private DNS zone in the hub VPC, and configure DNS forwarding to the on-premises
- BConfigure a DNS policy in the hub VPC to allow inbound query forwarding from the spoke VPCs.
- CConfigure a DNS policy in the spoke VPCs, and configure your on-premises DNS as an alternate
- DConfigure a DNS policy in the hub VPC, and configure the on-premises DNS as an alternate DNS
How the community answered
(50 responses)- A78% (39)
- B12% (6)
- C6% (3)
- D4% (2)
Explanation
https://cloud.google.com/dns/docs/best-practices#hybrid-architecture-using-hub-vpc-network- connected-to-spoke-vpc-networks
Topics
#Cloud DNS#Hybrid Networking#DNS Forwarding#Private DNS Zones
Community Discussion
No community discussion yet for this question.