Professional-Cloud-Network-Engineer Exam Question 51

You are trying to update firewall rules in a shared VPC for which you have been assigned only Network Admin permissions. You cannot modify the firewall rules. Your organization requires using the least privilege necessary.
Which level of permissions should you request?
  • Professional-Cloud-Network-Engineer Exam Question 52

    Your software team is developing an on-premises web application that requires direct connectivity to Compute Engine Instances in GCP using the RFC 1918 address space. You want to choose a connectivity solution from your on-premises environment to GCP, given these specifications:
    * Your ISP is a Google Partner Interconnect provider.
    * Your on-premises VPN device's internet uplink and downlink speeds are 10 Gbps.
    * A test VPN connection between your on-premises gateway and GCP is performing at a maximum speed of 500 Mbps due to packet losses.
    * Most of the data transfer will be from GCP to the on-premises environment.
    * The application can burst up to 1.5 Gbps during peak transfers over the Interconnect.
    * Cost and the complexity of the solution should be minimal.
    How should you provision the connectivity solution?
  • Professional-Cloud-Network-Engineer Exam Question 53

    You have an application running on Compute Engine that uses BigQuery to generate some results that are stored in Cloud Storage. You want to ensure that none of the application instances have external IP addresses.
    Which two methods can you use to accomplish this? (Choose two.)
  • Professional-Cloud-Network-Engineer Exam Question 54

    You are disabling DNSSEC for one of your Cloud DNS-managed zones. You removed the DS records from your zone file, waited for them to expire from the cache, and disabled DNSSEC for the zone. You receive reports that DNSSEC validating resolves are unable to resolve names in your zone.
    What should you do?
  • Professional-Cloud-Network-Engineer Exam Question 55

    You work for a multinational enterprise that is moving to GCP.
    These are the cloud requirements:
    * An on-premises data center located in the United States in Oregon and New York with Dedicated Interconnects connected to Cloud regions us-west1 (primary HQ) and us-east4 (backup)
    * Multiple regional offices in Europe and APAC
    * Regional data processing is required in europe-west1 and australia-southeast1
    * Centralized Network Administration Team
    Your security and compliance team requires a virtual inline security appliance to perform L7 inspection for URL filtering. You want to deploy the appliance in us-west1.
    What should you do?