Professional-Cloud-Network-Engineer Exam Question 131
You manage a Google Cloud VPC network that has multiple Cloud VPN tunnels connecting to a single branch office for redundancy. One tunnel is a new. high-performance link, while the other is an older, less reliable link. You need to configure dynamic routing to influence how your on- premises network routes traffic, ensuring it prefers sending traffic to Google Cloud over the new, high performance tunnel. The older tunnel must remain available as a backup. What should you do?
Professional-Cloud-Network-Engineer Exam Question 132
You are the network administrator responsible for hybrid connectivity at your organization. Your developer team wants to use Cloud SQL in the us-west1 region in your Shared VPC. You configured a Dedicated Interconnect connection and a Cloud Router in us-west1, and the connectivity between your Shared VPC and on-premises data center is working as expected. You just created the private services access connection required for Cloud SQL using the reserved IP address range and default settings. However, your developers cannot access the Cloud SQL instance from on-premises. You want to resolve the issue. What should you do?
Professional-Cloud-Network-Engineer Exam Question 133
You have configured a single IPSec Cloud VPN tunnel for your organization to one of your customers. The VPN Tunnel Status is showing as Established; however the BGP Session Status is showing as BGP not configured. Your customer's BGP settings are:
Customer BGP address: 169.254.11.1/30
Customer ASN: 64515
Google Cloud BGP address: 169.254.11.2
Google Cloud ASN: 64517
MD5 Authentication: Disabled
You need to configure your local BGP session for this tunnel based on the settings provided by the third party customer. You have already associated the Cloud Router with the Cloud VPN Tunnel. What should you do?
Customer BGP address: 169.254.11.1/30
Customer ASN: 64515
Google Cloud BGP address: 169.254.11.2
Google Cloud ASN: 64517
MD5 Authentication: Disabled
You need to configure your local BGP session for this tunnel based on the settings provided by the third party customer. You have already associated the Cloud Router with the Cloud VPN Tunnel. What should you do?
Professional-Cloud-Network-Engineer Exam Question 134
Your company runs its applications on Google Kubernetes Engine (GKE), and your team recently created a private Cloud DNS zone, corp.internal, to host records for internal services, such as a managed database at db.corp.internal. You verified that a Compute Engine VM in the same VPC as your GKE cluster can successfully resolve db.corp.internal. However, when you access a Pod inside your GKE cluster, you can resolve in-cluster services (for example, kubernetes.default.svc.cluster.local), but any attempt to resolve db.corp.internal fails.
Upon inspecting the coredns ConfigMap in the kube-system namespace, you discovered the default forward plugin has been modified to point directly to a public DNS provider's IP address, bypassing the node's local resolver. You need to enable Pods in the cluster to resolve records in the existing corp.internal private zone as well as other zones under .internal.
Upon inspecting the coredns ConfigMap in the kube-system namespace, you discovered the default forward plugin has been modified to point directly to a public DNS provider's IP address, bypassing the node's local resolver. You need to enable Pods in the cluster to resolve records in the existing corp.internal private zone as well as other zones under .internal.
Professional-Cloud-Network-Engineer Exam Question 135
Your organization has approximately 100 teams that need to manage their own environments. A central team must manage the network. You need to design a landing zone that provides separate projects for each team. You must also make sure the solution can scale. What should you do?
