Professional-Cloud-Network-Engineer Exam Question 41

Your organization wants to deploy HA VPN over Cloud Interconnect to ensure encryption-in- transit over the Cloud Interconnect connections. You have created a Cloud Router and two encrypted VLAN attachments that have a 5 Gbps capacity and a BGP configuration. The BGP sessions are operational. You need to complete the deployment of the HA VPN over Cloud Interconnect. What should you do?
  • Professional-Cloud-Network-Engineer Exam Question 42

    You recently reviewed the user behavior for your main application, which uses an external global Application Load Balancer, and found that the backend servers were overloaded due to erratic spikes in the rate of client requests. You need to limit the concurrent sessions and return an HTTP 429 Too Many Requests response back to the client while following Google-recommended practices. What should you do?
  • Professional-Cloud-Network-Engineer Exam Question 43

    Your company's current network deployment is composed of a single VPC that is connected to a single data center by a Dedicated Interconnect connection. The Dedicated Interconnect topology has a 99.9% SLA. There is a single VLAN attachment for each of the two Dedicated Interconnect links. All VLAN attachments only use IPv4 addresses. Between the data center and the VPC, only IPv4 routes are exchanged by BGP.
    You need to create a solution to exchange IPV6 routes between the data center and the VPC.
    You must use a procedure that requires the least amount of setup effort and minimizes costs. It's impossible to add new BGP peers to the configuration of the on-premises routers. Only modifications of the existing BGP peers are possible.
    What should you do?
  • Professional-Cloud-Network-Engineer Exam Question 44

    Your organization's security policy requires that all internet-bound traffic return to your on- premises data center through HA VPN tunnels before egressing to the internet, while allowing virtual machines (VMs) to leverage private Google APIs using private virtual IP addresses
    199.36.153.4/30. You need to configure the routes to enable these traffic flows. What should you do?
  • Professional-Cloud-Network-Engineer Exam Question 45

    You are designing an IP address scheme for new private Google Kubernetes Engine (GKE) clusters. Due to IP address exhaustion of the RFC 1918 address space in your enterprise, you plan to use privately used public IP space for the new clusters. You want to follow Google- recommended practices. What should you do after designing your IP scheme?