Professional-Cloud-Network-Engineer Exam Question 86
You are deploying an application on a fleet of Compute Engine virtual machines (VMs) that must process sensitive, financial data by communicating with the Cloud Storage API. The VMs currently have internal IP addresses. You need to enable this communication using the most secure method available. What should you do? (Choose two.)
Professional-Cloud-Network-Engineer Exam Question 87
You have a Cloud Storage bucket in Google Cloud project XYZ. The bucket contains sensitive data.
You need to design a solution to ensure that only instances belonging to VPCs under project XYZ can access the data stored in this Cloud Storage bucket. What should you do?
You need to design a solution to ensure that only instances belonging to VPCs under project XYZ can access the data stored in this Cloud Storage bucket. What should you do?
Professional-Cloud-Network-Engineer Exam Question 88
You have a data workflow which consists of data ingestion layer, data transformation layer, data analytics layer and data storage layer. You are looking for a service that would ease the tasks of creating, scheduling, monitoring and managing workflows without dealing with the management of the infrastructure .Please select the right service that would fulfil the requirement.
Professional-Cloud-Network-Engineer Exam Question 89
You have several VMs across multiple VPCs in your cloud environment, which require access to internet endpoints. These VMs cannot have public IP addresses due to security policies, so you plan to use Cloud NAT to provide outbound internet access. Within your VPCs, you have several subnets in each region. You want to ensure that only specific subnets have access to the internet through Cloud NAT. You want to avoid any unintentional configuration issues caused by other administrators, and align to Google-recommended practices. What should you do?
Professional-Cloud-Network-Engineer Exam Question 90
Your organization has a legacy VPN device that uses IKEv1 and does not support BGP.
Connectivity from your on-premises environment to Google Cloud needs to be established. You are using 172.16.100.0/24, 172.16.101.0/24, and 172.16.102.0/24 in your on-premises environment, and 192.168.100.0/24, 192.168.101.0/24, and 192.168.102.0/24 in your Google Cloud environment. You have configured a VPN gateway and you need to configure a policy- based VPN tunnel. What should you do?
Connectivity from your on-premises environment to Google Cloud needs to be established. You are using 172.16.100.0/24, 172.16.101.0/24, and 172.16.102.0/24 in your on-premises environment, and 192.168.100.0/24, 192.168.101.0/24, and 192.168.102.0/24 in your Google Cloud environment. You have configured a VPN gateway and you need to configure a policy- based VPN tunnel. What should you do?
