Professional Cloud Network Engineer - Google Cloud Certified Logo
Google Logo

Professional Cloud Network Engineer - Google Cloud Certified Exam Questions

274

Total Questions

SEP
2025

Last Updated

1st

1st Try Guaranteed

Expert Verified

Experts Verified

Question 11 Multiple Choice

Your task involves configuring your organization's Google Cloud environment to connect to your on-premises network, which lacks support for Border Gateway Protocol (BGP). The on-premises network comprises 30 CIDR ranges that must be accessible from Google Cloud. Additionally, your VPN gateway generates a unique child security association (SA) per CIDR. It's imperative to ensure the reachability of all 30 CIDR ranges from Google Cloud, following Google's recommended practices.

Which two methods can achieve this goal? (Select two options.)

Question 12 Single Choice

You are architecting a new application where the backend services are internally accessible on port 800. This application must be externally available over both IPv4 and IPv6, using TCP on port 700. The solution must be designed with high availability in mind.

Which configuration should you choose?

Question 13 Single Choice

You've recently deployed Compute Engine instances in the us-west1 and us-east1 regions within a Virtual Private Cloud (VPC) utilizing default routing configurations. However, your company's security policy strictly prohibits virtual machines (VMs) from having public IP addresses. Your objective is to enable these instances to fetch updates from the internet while safeguarding against external access. What is the most appropriate course of action?

Question 14 Single Choice

You need to set up a static route to an on-premises resource behind a Cloud VPN gateway that employs policy-based routing via the gcloud command. Which next hop should you choose?

Question 15 Single Choice

To comply with your organization's security policy, which mandates that all internet-bound traffic returns to your on-premises data center via HA VPN tunnels before accessing the internet, and that virtual machines (VMs) can utilize private Google APIs using private virtual IP addresses 199.36.153.4/30, how should you configure the routes to facilitate these traffic patterns?

Question 16 Single Choice

When deploying a global external TCP load balancing solution and aiming to retain the original layer 3 payload's source IP address, which type of load balancer should you opt for?

Question 17 Multiple Choice

Your organization is collaborating with a partner to deliver a solution for a client. Both entities utilize Google Cloud Platform (GCP). Within the partner's network, there are applications requiring access to certain resources within your company's Virtual Private Cloud (VPC). Notably, there is no CIDR overlap between the VPCs. How can you achieve this connectivity requirement while maintaining security? Select two options.

Question 18 Single Choice

Which option should you select to create a direct connection to Google for accessing Cloud SQL through a public IP address without relying on a third-party service provider?

Question 19 Single Choice

You've implemented a new internal application offering HTTP and TFTP services to on-premises hosts. To distribute traffic across several Compute Engine instances while ensuring clients remain connected to a specific instance across both services, what session affinity option should you select?

Question 20 Single Choice

You have two routers in your on-premises data center, both connected to Google Cloud Platform (GCP) via VPNs. However, despite having two connections, all traffic is routed through a single VPN instead of being evenly distributed across both connections. Your troubleshooting reveals the following:

- Both on-premises routers have the same Autonomous System Number (ASN).
- The routing tables and priorities are identical on both on-premises routers.
- Each on-premises router has a VPN configured, both connecting to a single Cloud Router.
- VPN logs indicate "no-proposal-chosen" lines during connection attempts.
- One of the on-premises routers fails to establish a BGP session with the Cloud Router.

What is the most probable cause of this issue?

Page: 2 / 28