Your organization wants to deploy HA VPN over Cloud Interconnect to ensure encryption-in- transit over the Cloud Interconnect connections. You have created a Cloud Router and two VLAN attachments. The BGP sessions are operational. You need to complete the deployment of the HA VPN over Cloud Interconnect. What should you do?
Correct Answer: B
HA VPN over Cloud Interconnect requires two separate Cloud Router instances - one dedicated to the Interconnect VLAN attachments and a second one for the HA VPN tier. To finish your deployment, you must: 1. Create an HA VPN gateway and associate its two interfaces with your encrypted VLAN attachments. 2. Provision a new Cloud Router for the HA VPN tier (you cannot reuse the Interconnect-tier router). 3. Configure the peer VPN gateway resources and HA VPN tunnels against that new router. This separation ensures the Interconnect BGP session remains distinct from your HA VPN BGP session, as documented by Google's HA VPN over Cloud Interconnect architecture.
You work for a organization called cloudtech5 . Your organization has decided to implement continuous integration and delivery (CI/CD) pipeline on Google Cloud Platform using only hosted products and the popular GitOps methodology . The architecture includes many microservices that are updated frequently and rolled back . Please select the products that should be used.
Correct Answer: A
Option A is the Correct choice because , Cloud Source repositories is a a fully featured, scalable, private Git repository hosted on Google Cloud . Cloud Build is a service that executes your builds on Google Cloud Platform infrastructure. Cloud Build can import source code from Google Cloud Storage, Cloud Source Repositories, GitHub, or Bitbucket, execute a build to your specifications, and produce artifacts such as Docker containers or Java archives. Container Registry is a private container image registry that runs on Google Cloud Platform. Google Kuberenetes Engine is ideal for deploying small services that can be updated and rolled back quickly. Option B is Incorrect because , BitBucket isn't Google Cloud hosted service but it can be used to achieve the same results . Option C is Incorrect because Jenkins on Compute Engine isn't Google hosted product , Cloud build is the right choice because it is a service managed by Google Cloud . Option D is Incorrect because , the objective is to implement CI/CD pipeline not data processing pipeline .
You are configuring the final elements of a migration effort where resources have been moved from on-premises to Google Cloud. While reviewing the deployed architecture, you noticed that DNS resolution is failing when queries are being sent to the on-premises environment. You login to a Compute Engine instance, try to resolve an on-premises hostname, and the query fails. DNS queries are not arriving at the on-premises DNS server. You need to use managed services to reconfigure Cloud DNS to resolve the DNS error. What should you do?
Correct Answer: C
To ensure DNS queries from Google Cloud resources can resolve on-premises hostnames, you should leverage Google Cloud's managed DNS services and properly configure DNS forwarding. Here's why: Validate the resolver: Ensure that Compute Engine instances are using the Metadata Service IP address (169.254.169.254) as their DNS resolver. This allows DNS queries to flow through Cloud DNS. Configure an outbound forwarding zone: In Cloud DNS, create a forwarding zone for the on- premises domain. This ensures that DNS queries for the on-premises domain are forwarded to the on-premises DNS server. Cloud Router configuration: Advertise the Cloud DNS proxy range to the on-premises network via Cloud Router. This step ensures that DNS queries originating from the on-premises environment for Google Cloud services are resolved correctly and vice versa.
The applications in your Google Cloud environment and your AWS cloud environment frequently exchange large volumes of data, and the existing Cloud VPN connections are not meeting the required throughput and reliability. You need to establish high-performance, low-latency, highly available connectivity between your Google Cloud environment and your AWS cloud environment. You also need to create a dedicated, private connection between your Google Cloud VPC and your AWS VPC. What should you do?
Correct Answer: C
Cross-Cloud Interconnect is designed for private, dedicated connectivity between Google Cloud and another cloud provider such as AWS. It provides high-bandwidth, low-latency connectivity and supports BGP peering over the dedicated connection between your Google Cloud VPC and AWS environment. This fits the requirement for a dedicated, private, highly available connection better than Cloud VPN, while avoiding the extra complexity of assembling separate interconnect products through a colocation design yourself Reference: https://docs.cloud.google.com/network-connectivity/docs/interconnect/how-to/cci/aws/connectivity-overview https://docs.cloud.google.com/network-connectivity/docs/interconnect/concepts/cci-overview
You are configuring HA VPN for your organization to connect your on-premises environment to your Google Cloud network. Your on-premises environment is closest to the us-west1 Google Cloud region. You have Google Cloud resources in us-west2, which requires a throughput of 300,000 packets per second (PPS) and an approximate bandwidth of 4 Gbps. You need to have predictable bandwidth management and maintain an SLA of 99.99% with minimal costs. What should you do?
Correct Answer: B
HA VPN throughput and redundancy requirements: Each HA VPN gateway can support a maximum of 3 Gbps of throughput per gateway with two tunnels in active/active mode. Since your requirement is approximately 4 Gbps of bandwidth and 300,000 PPS, one HA VPN gateway would not suffice. Using two HA VPN gateways ensures sufficient capacity to handle the required throughput. SLA of 99.99%: To achieve a 99.99% SLA, you need to configure HA VPN with two tunnels per gateway in active/active mode (equal routing priority). This ensures redundancy, load distribution, and high availability. BGP configuration for load balancing: - By configuring the base routing priority metric (100) equally on both tunnels of each gateway, you ensure that traffic is evenly distributed across all tunnels. - On the on-premises router, configure the same multi-exit discriminator (MED) values for all tunnels to maintain consistent routing behavior.