nerdexam
Google

PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #118

Your organization uses a hub-and-spoke architecture with critical Compute Engine instances in your Virtual Private Clouds (VPCs). You are responsible for the design of Cloud DNS in Google Cloud. You…

The correct answer is A. Configure a private DNS zone in the hub VPC, and configure DNS forwarding to the on-premises. https://cloud.google.com/dns/docs/best-practices#hybrid-architecture-using-hub-vpc-network- connected-to-spoke-vpc-networks

Submitted by wei.xz· Apr 18, 2026Designing, planning, and prototyping a Google Cloud network

Question

Your organization uses a hub-and-spoke architecture with critical Compute Engine instances in your Virtual Private Clouds (VPCs). You are responsible for the design of Cloud DNS in Google Cloud. You need to be able to resolve Cloud DNS private zones from your on-premises data center and enable on-premises name resolution from your hub-and-spoke VPC design. What should you do?

Options

  • AConfigure a private DNS zone in the hub VPC, and configure DNS forwarding to the on-premises
  • BConfigure a DNS policy in the hub VPC to allow inbound query forwarding from the spoke VPCs.
  • CConfigure a DNS policy in the spoke VPCs, and configure your on-premises DNS as an alternate
  • DConfigure a DNS policy in the hub VPC, and configure the on-premises DNS as an alternate DNS

How the community answered

(50 responses)
  • A
    78% (39)
  • B
    12% (6)
  • C
    6% (3)
  • D
    4% (2)

Explanation

https://cloud.google.com/dns/docs/best-practices#hybrid-architecture-using-hub-vpc-network- connected-to-spoke-vpc-networks

Topics

#Cloud DNS#Hybrid Networking#DNS Forwarding#Private DNS Zones

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-NETWORK-ENGINEER Practice