Professional-Cloud-Network-Engineer Exam Question 76

You want to configure a NAT to perform address translation between your on-premises network blocks and GCP.
Which NAT solution should you use?
  • Professional-Cloud-Network-Engineer Exam Question 77

    You are designing a Google Kubernetes Engine (GKE) cluster for your organization. The current cluster size is expected to host 10 nodes, with 20 Pods per node and 150 services. Because of the migration of new services over the next 2 years, there is a planned growth for 100 nodes, 200 Pods per node, and 1500 services. You want to use VPC-native clusters with alias IP ranges, while minimizing address consumption.
    How should you design this topology?
  • Professional-Cloud-Network-Engineer Exam Question 78

    You need to create a new VPC network that allows instances to have IP addresses in both the 10.1.1.0/24 network and the 172.16.45.0/24 network.
    What should you do?
  • Professional-Cloud-Network-Engineer Exam Question 79

    Your organization is implementing a new security policy to control how firewall rules are applied to control flows between virtual machines (VMs). Using Google-recommended practices, you need to set up a firewall rule to enforce strict control of traffic between VM A and VM B.
    You must ensure that communications flow only from VM A to VM B within the VPC, and no other communication paths are allowed. No other firewall rules exist in the VPC. Which firewall rule should you configure to allow only this communication path?
  • Professional-Cloud-Network-Engineer Exam Question 80

    All the instances in your project are configured with the custom metadata enable-oslogin value set to FALSE and to block project-wide SSH keys. None of the instances are set with any SSH key, and no project-wide SSH keys have been configured. Firewall rules are set up to allow SSH sessions from any IP address range. You want to SSH into one instance.
    What should you do?