nerdexam
Google

PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #242

You are configuring an Application Load Balancer. The backend resides in your on-premises data center and is connected by Dedicated Interconnect. You need to ensure the load balancer can reference…

The correct answer is C. Configure a hybrid network endpoint group (NEG) as a backend service as part of the load. To ensure the Application Load Balancer can reference on-premises resources without traffic traversing the internet, you should configure a hybrid network endpoint group (NEG). Hybrid NEGs allow you to include on-premises endpoints connected through Dedicated Interconnect or…

Submitted by brentm· Apr 18, 2026Configuring network services

Question

You are configuring an Application Load Balancer. The backend resides in your on-premises data center and is connected by Dedicated Interconnect. You need to ensure the load balancer can reference these on-premises resources. You do not want the traffic to traverse the internet at all. What should you do?

Options

  • AConfigure an internet network endpoint group (NEG) as a backend service as part of the load
  • BConfigure a zonal network endpoint group (NEG) as a backend service as part of the load
  • CConfigure a hybrid network endpoint group (NEG) as a backend service as part of the load
  • DConfigure a Private Service Connect network endpoint group (NEG) as a backend service as part

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    6% (1)
  • C
    76% (13)
  • D
    12% (2)

Explanation

To ensure the Application Load Balancer can reference on-premises resources without traffic traversing the internet, you should configure a hybrid network endpoint group (NEG). Hybrid NEGs allow you to include on-premises endpoints connected through Dedicated Interconnect or VPN as part of the backend for the load balancer. Traffic from the load balancer will use the private connection (Dedicated Interconnect) to reach the on-premises resources. Opening the firewalls for the proxy-only subnet ensures that the load balancer can connect to the backend securely while keeping traffic internal and off the public internet.

Topics

#Application Load Balancer#Network Endpoint Group (NEG)#Hybrid Connectivity#On-premises integration

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-NETWORK-ENGINEER Practice