Professional-Cloud-Network-Engineer Exam Question 61

Your company has a security team that manages firewalls and SSL certificates. It also has a networking team that manages the networking resources. The networking team needs to be able to read firewall rules, but should not be able to create, modify, or delete them.
How should you set up permissions for the networking team?
  • Professional-Cloud-Network-Engineer Exam Question 62

    Your on-premises data center has 2 routers connected to your GCP through a VPN on each router. All applications are working correctly; however, all of the traffic is passing across a single VPN instead of being load-balanced across the 2 connections as desired.
    During troubleshooting you find:
    * Each on-premises router is configured with the same ASN.
    * Each on-premises router is configured with the same routes and priorities.
    * Both on-premises routers are configured with a VPN connected to a single Cloud Router.
    * The VPN logs have no-proposal-chosen lines when the VPNs are connecting.
    * BGP session is not established between one on-premises router and the Cloud Router.
    What is the most likely cause of this problem?
  • Professional-Cloud-Network-Engineer Exam Question 63

    In your company, two departments with separate GCP projects (code-dev and data-dev) in the same organization need to allow full cross-communication between all of their virtual machines in GCP. Each department has one VPC in its project and wants full control over their network. Neither department intends to recreate its existing computing resources. You want to implement a solution that minimizes cost.
    Which two steps should you take? (Choose two.)
  • Professional-Cloud-Network-Engineer Exam Question 64

    You need to enable Private Google Access for use by some subnets within your Virtual Private Cloud (VPC). Your security team set up the VPC to send all internet-bound traffic back to the on- premises data center for inspection before egressing to the internet, and is also implementing VPC Service Controls in the environment for API-level security control. You have already enabled the subnets for Private Google Access. What configuration changes should you make to enable Private Google Access while adhering to your security team's requirements?
  • Professional-Cloud-Network-Engineer Exam Question 65

    Your organization has a single project that contains multiple Virtual Private Clouds (VPCs). You need to secure API access to your Cloud Storage buckets and BigQuery datasets by allowing API access only from resources in your corporate public networks. What should you do?