Professional-Cloud-Network-Engineer Exam Question 16
Your company acquired a new division. The new division's network team requires complete control over their networking infrastructure. You need to extend your existing Google Cloud network infrastructure, that consists of a single VPC, to allow workloads from all divisions to communicate with each other. You want to avoid incurring extra costs and granting unnecessary permissions to the new division's networking team. What should you do?
Professional-Cloud-Network-Engineer Exam Question 17
Your organization is developing a landing zone architecture with the following requirements:
- There should be no communication possible between production and non- production environments.
- Communication between applications within an environment may be
necessary.
- Network administrators should centrally manage all network resources, including subnets, routes, and firewall rules.
- Each application should be billed separately.
- Developers of an application within a project should have the
autonomy to create their compute resources. They should not create or
modify networking resources.
- Up to 1000 applications are expected per environment.
You need to create a design that accommodates these requirements. What should you do?
- There should be no communication possible between production and non- production environments.
- Communication between applications within an environment may be
necessary.
- Network administrators should centrally manage all network resources, including subnets, routes, and firewall rules.
- Each application should be billed separately.
- Developers of an application within a project should have the
autonomy to create their compute resources. They should not create or
modify networking resources.
- Up to 1000 applications are expected per environment.
You need to create a design that accommodates these requirements. What should you do?
Professional-Cloud-Network-Engineer Exam Question 18
Your company has a single Virtual Private Cloud (VPC) network deployed in Google Cloud with on-premises connectivity already in place. You are deploying a new application using Google Kubernetes Engine (GKE), which must be accessible only from the same VPC network and on- premises locations. You must ensure that the GKE control plane is exposed to a predefined list of on-premises subnets through private connectivity only. What should you do?
Professional-Cloud-Network-Engineer Exam Question 19
As part of your organization's modernization efforts, the application teams are migrating services to GKE on Google Cloud (GKE). The GKE clusters will live in service projects. The teams have validated the applications and configurations in their sandbox projects. When moving to production, you noticed that GKE nodes were not being created. Users were able to create Compute Engine instances, but the operation failed when they tried to create a GKE cluster. You need to enable the application teams so they can create said GKE clusters. What should you do?
Professional-Cloud-Network-Engineer Exam Question 20
You want to apply a new Cloud Armor policy to an application that is deployed in Google Kubernetes Engine (GKE). You want to find out which target to use for your Cloud Armor policy.
Which GKE resource should you use?
Which GKE resource should you use?
