Professional-Cloud-Network-Engineer Exam Question 51

You created a new VPC for your development team. You want to allow access to the resources in this VPC via SSH only.
How should you configure your firewall rules?
  • Professional-Cloud-Network-Engineer Exam Question 52

    You want to apply a new Cloud Armor policy to an application that is deployed in Google Kubernetes Engine (GKE). You want to find out which target to use for your Cloud Armor policy.
    Which GKE resource should you use?
  • Professional-Cloud-Network-Engineer Exam Question 53

    Your on-premises data center has 2 routers connected to your Google Cloud environment through a VPN on each router. All applications are working correctly; however, all of the traffic is passing across a single VPN instead of being load-balanced across the 2 connections as desired.
    During troubleshooting you find:
    - Each on-premises router is configured with a unique ASN. ?Each on-
    premises router is configured with the same routes and priorities.
    - Both on-premises routers are configured with a VPN connected to a
    single Cloud Router.
    - BGP sessions are established between both on-premises routers and the Cloud Router.
    - Only 1 of the on-premises router's routes are being added to the
    routing table.
    What is the most likely cause of this problem?
  • Professional-Cloud-Network-Engineer Exam Question 54

    You are creating an instance group and need to create a new health check for HTTP(s) load balancing.
    Which two methods can you use to accomplish this? (Choose two.)
  • Professional-Cloud-Network-Engineer Exam Question 55

    You are deploying an application that runs on Compute Engine instances. You need to determine how to expose your application to a new customer You must ensure that your application meets the following requirements
    * Maps multiple existing reserved external IP addresses to the Instance
    * Processes IP Encapsulating Security Payload (ESP) traffic
    What should you do?