Professional-Cloud-Network-Engineer Exam Question 96

You are designing a solution to inspect all traffic between your company's production-vpc and development-vpc for threat detection and compliance logging. The company will deploy a fleet of third-party Cloud Next Generation Firewall (NGFW) appliances that provide intrusion prevention system (IPS) capabilities. You need to prevent attacks by blocking malicious traffic in real time before it reaches its destination without adding significant latency or creating a single point of failure for inter-VPC communication. What should you do?
  • Professional-Cloud-Network-Engineer Exam Question 97

    Your company has a single Virtual Private Cloud (VPC) network deployed in Google Cloud with access from your on-premises network using Cloud Interconnect. You must configure access only to Google APIs and services that are supported by VPC Service Controls through hybrid connectivity with a service level agreement (SLA) in place. What should you do?
  • Professional-Cloud-Network-Engineer Exam Question 98

    Your organization has deployed Google Kubernetes Engine (GKE) clusters in several different Virtual Private Clouds (VPCs) for the past year, one GKE cluster per VPC. While the GKE nodes leverage unique IP space between each cluster, the Pod IP ranges have been reused across VPCs. The VPCs are spokes of a Network Connectivity Center hub configured in mesh topology.
    The Pod IP ranges have been excluded from the Network Connectivity Center VPC spokes.
    While this process seems to work and Compute Engine instances in the VPCs can reach services, you notice that the Pods are unable to access services in other VPCs. You need to enable communication between Pods in different VPCs. What should you do?
  • Professional-Cloud-Network-Engineer Exam Question 99

    You configured Cloud VPN with dynamic routing via Border Gateway Protocol (BGP). You added a custom route to advertise a network that is reachable over the VPN tunnel. However, the on- premises clients still cannot reach the network over the VPN tunnel. You need to examine the logs in Cloud Logging to confirm that the appropriate routers are being advertised over the VPN tunnel. Which filter should you use in Cloud Logging to examine the logs?
  • Professional-Cloud-Network-Engineer Exam Question 100

    You are migrating a three-tier application architecture from on-premises to Google Cloud. As a first step in the migration, you want to create a new Virtual Private Cloud (VPC) with an external HTTP(S) load balancer. This load balancer will forward traffic back to the on-premises compute resources that run the presentation tier. You need to stop malicious traffic from entering your VPC and consuming resources at the edge, so you must configure this policy to filter IP addresses and stop cross-site scripting (XSS) attacks. What should you do?