nerdexam
Google

PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #231

PROFESSIONAL-CLOUD-NETWORK-ENGINEER Question #231: Real Exam Question with Answer & Explanation

Sign in or unlock PROFESSIONAL-CLOUD-NETWORK-ENGINEER to reveal the answer and full explanation for question #231. The question stem and answer options stay visible for context.

Submitted by emma.c· Apr 18, 2026Configuring network services

Question

Your organization's application is running on a VPC-native GKE Standard cluster with public IP addresses. You need to configure access to the remote address range 35.100.0.0/16 through Cloud NAT, instead of using the GKE nodes' external IP addresses. SNAT is enabled on the cluster and needs to be configured. What should you do?

Options

  • AConfigure nonMasqueradeCIDRs in the ip-masq-agent ConfigMap. Include the 35.100.0.0/16
  • BConfigure nonMasqueradeCIDRs in the ip-masq-agent ConfigMap. Remove the 35.100.0.0/16
  • CConfigure Cloud NAT and create an exclusion rule for any SNAT address translation.
  • DConfigure Cloud NAT with nonMasqueradeCIDRs, and enable SNAT with the same configuration

Unlock PROFESSIONAL-CLOUD-NETWORK-ENGINEER to see the answer

You've previewed enough free PROFESSIONAL-CLOUD-NETWORK-ENGINEER questions. Unlock PROFESSIONAL-CLOUD-NETWORK-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#GKE Networking#Cloud NAT#SNAT#ip-masq-agent
Full PROFESSIONAL-CLOUD-NETWORK-ENGINEER Practice