Professional-Cloud-Network-Engineer Exam Question 56

You created a new VPC network named Dev with a single subnet. You added a firewall rule for the network Dev to allow HTTP traffic only and enabled logging. When you try to log in to an instance in the subnet via Remote Desktop Protocol, the login fails. You look for the Firewall rules logs in Stackdriver Logging, but you do not see any entries for blocked traffic. You want to see the logs for blocked traffic.
What should you do?
  • Professional-Cloud-Network-Engineer Exam Question 57

    You want to apply a new Cloud Armor policy to an application that is deployed in Google Kubernetes Engine (GKE). You want to find out which target to use for your Cloud Armor policy.
    Which GKE resource should you use?
  • Professional-Cloud-Network-Engineer Exam Question 58

    You need to create a GKE cluster in an existing VPC that is accessible from on-premises. You must meet the following requirements:
    * IP ranges for pods and services must be as small as possible.
    * The nodes and the master must not be reachable from the internet.
    * You must be able to use kubectl commands from on-premises subnets to manage the cluster.
    How should you create the GKE cluster?
  • Professional-Cloud-Network-Engineer Exam Question 59

    Your company has recently expanded their EMEA-based operations into APAC. Globally distributed users report that their SMTP and IMAP services are slow. Your company requires end-to-end encryption, but you do not have access to the SSL certificates.
    Which Google Cloud load balancer should you use?
  • Professional-Cloud-Network-Engineer Exam Question 60

    You have recently been put in charge of managing identity and access management for your organization. You have several projects and want to use scripting and automation wherever possible. You want to grant the editor role to a project member.
    Which two methods can you use to accomplish this? (Choose two.)
    GetIamPolicy() via REST API