Professional-Cloud-Network-Engineer Exam Question 106
You are implementing a VPC architecture for your organization by using a Network Connectivity Center hub and spoke topology:
- There is one Network Connectivity Center hybrid spoke to receive on-
premises routes.
- There is one VPC spoke that needs to be added as a Network
Connectivity Center spoke.
Your organization has limited routable IP space for their cloud environment (192.168.0.0/20). The Network Connectivity Center spoke VPC is connected to on-premises with a Cloud Interconnect connection in the us-east4 region. The on-premises IP range is 172.16.0.0/16. You need to reach on-premises resources from multiple Google Cloud regions (us-west1,europe-central1, and asia- southeast1) and minimize the IP addresses being used. What should you do?
- There is one Network Connectivity Center hybrid spoke to receive on-
premises routes.
- There is one VPC spoke that needs to be added as a Network
Connectivity Center spoke.
Your organization has limited routable IP space for their cloud environment (192.168.0.0/20). The Network Connectivity Center spoke VPC is connected to on-premises with a Cloud Interconnect connection in the us-east4 region. The on-premises IP range is 172.16.0.0/16. You need to reach on-premises resources from multiple Google Cloud regions (us-west1,europe-central1, and asia- southeast1) and minimize the IP addresses being used. What should you do?
Professional-Cloud-Network-Engineer Exam Question 107
You are establishing a hybrid connection between your on-premises data center and Google Cloud. You configured a Cloud DNS private zone and an inbound server policy in your primary VPC to allow on-premises hosts to resolve private DNS zones hosted in Google Cloud, such as vm.gcp.corp.internal. The inbound server policy has been assigned an IP address, and you have configured your on-premises DNS servers to conditionally forward requests for the gcp.corp.internal domain to this IP.
From your on-premises network, you can see that the routes for the inbound forwarding addresses were learned as expected, and response traffic is correctly being routed through your on-premises edge firewall to GCP. However, all DNS queries from on-premises clients for this domain are timing out, and they are unable to resolve the addresses of any Google Cloud resources.
What should you do?
From your on-premises network, you can see that the routes for the inbound forwarding addresses were learned as expected, and response traffic is correctly being routed through your on-premises edge firewall to GCP. However, all DNS queries from on-premises clients for this domain are timing out, and they are unable to resolve the addresses of any Google Cloud resources.
What should you do?
Professional-Cloud-Network-Engineer Exam Question 108
Your organization's current architecture has one Shared VPC host project (SH_HOST_PRJ) that contains a single VPC (SH_VPC) and two Shared VPC service projects (SP_ONE_PRJ and SP_TWO_PRJ) that do not contain any VPCs. Each Shared VPC service project belongs to a different team: TEAM_ONE manages SP_ONE_PRJ and TEAM_TWO manages SP_TWO_PRJ.
You must design a solution that allows each team to create their own DNS private zones and DNS records only in their respective Shared VPC service projects. Workloads in SP_ONE_PRJ must be able to resolve all the DNS private zones defined in SP_TWO_PRJ and conversely. Your design must have the least amount of set up effort. What should you do?
You must design a solution that allows each team to create their own DNS private zones and DNS records only in their respective Shared VPC service projects. Workloads in SP_ONE_PRJ must be able to resolve all the DNS private zones defined in SP_TWO_PRJ and conversely. Your design must have the least amount of set up effort. What should you do?
Professional-Cloud-Network-Engineer Exam Question 109
You correctly configured Cloud DNS forwarding zones to point towards your on-premises DNS.
You noticed that you cannot query your on-premises Active Directory main Domain Controller by using "dig ad.company.int" over your interconnect attachment. However, the query is successful if you directly target your on-premises DNS server by using "dig @10.10.10.53 ad.company.int".
You need to correctly configure Cloud DNS so VMs and other resources can correctly resolve DNS records in your on-premises DNS system. What should you do?
You noticed that you cannot query your on-premises Active Directory main Domain Controller by using "dig ad.company.int" over your interconnect attachment. However, the query is successful if you directly target your on-premises DNS server by using "dig @10.10.10.53 ad.company.int".
You need to correctly configure Cloud DNS so VMs and other resources can correctly resolve DNS records in your on-premises DNS system. What should you do?
Professional-Cloud-Network-Engineer Exam Question 110
Your organization has five different VPCs across different projects in y our Google Cloud organization that need high-throughput connectivity. You have performed an audit of the IP address utilization in each VPC, and there are two overlapping subnets that are used by two of the VPCs: 240.0.0.0/16 and 240.128.0.0/24. You have confirmed that no Class E subnets (240.0.0.0/4) will require inter-VPC connectivity, but all other subnets in the VPCs will need connectivity. You need to deploy a Google Cloud routing solution to meet the connectivity requirements. What should you do?
