Professional-Cloud-Network-Engineer Exam Question 106

Your on-premises data center has 2 routers connected to your Google Cloud environment through a VPN on each router. All applications are working correctly; however, all of the traffic is passing across a single VPN instead of being load-balanced across the 2 connections as desired.
During troubleshooting you find:
* Each on-premises router is configured with a unique ASN.
* Each on-premises router is configured with the same routes and priorities.
* Both on-premises routers are configured with a VPN connected to a single Cloud Router.
* BGP sessions are established between both on-premises routers and the Cloud Router.
* Only 1 of the on-premises router's routes are being added to the routing table.
What is the most likely cause of this problem?
  • Professional-Cloud-Network-Engineer Exam Question 107

    Your company's security team wants to limit the type of inbound traffic that can reach your web servers to protect against security threats. You need to configure the firewall rules on the web servers within your Virtual Private Cloud (VPC) to handle HTTP and HTTPS web traffic for TCP only. What should you do?
  • Professional-Cloud-Network-Engineer Exam Question 108

    You are responsible for configuring firewall policies for your company in Google Cloud. Your security team has a strict set of requirements that must be met to configure firewall rules.
    Always allow Secure Shell (SSH) from your corporate IP address.
    Restrict SSH access from all other IP addresses.
    There are multiple projects and VPCs in your Google Cloud organization. You need to ensure that other VPC firewall rules cannot bypass the security team's requirements. What should you do?
  • Professional-Cloud-Network-Engineer Exam Question 109

    You need to ensure your personal SSH key works on every instance in your project. You want to accomplish this as efficiently as possible.
    What should you do?
  • Professional-Cloud-Network-Engineer Exam Question 110

    You want to deploy a VPN Gateway to connect your on-premises network to GCP. You are using a non BGP- capable on-premises VPN device. You want to minimize downtime and operational overhead when your network grows. The device supports only IKEv2, and you want to follow Google-recommended practices.
    What should you do?