
[Mar-2024] Free Professional-Cloud-Network-Engineer Exam Dumps to Improve Exam Score
2024 Realistic Professional-Cloud-Network-Engineer Dumps Exam Tips Test Pdf Exam Material
Prerequisites
The Google Professional Cloud Network Engineer certification exam is designed for the specialists who work on Cloud or networking teams with the architects designing the infrastructure. There are no obligatory requirements that the candidates need to meet to go for this test. Nevertheless, some industry experience will be a benefit. It is recommended that the applicants have at least three years of professional experience, including one or more years designing and managing solutions with the help of Google Cloud Platform.
NEW QUESTION # 45
You want to apply a new Cloud Armor policy to an application that is deployed in Google Kubernetes Engine (GKE). You want to find out which target to use for your Cloud Armor policy.
Which GKE resource should you use?
- A. GKE Node
- B. GKE Ingress
- C. GKE Pod
- D. GKE Cluster
Answer: B
Explanation:
Cloud Armour is applied at load balancers Configuring Google Cloud Armor through Ingress. https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-features Security policy features Google Cloud Armor security policies have the following core features: You can optionally use the QUIC protocol with load balancers that use Google Cloud Armor. You can use Google Cloud Armor with external HTTP(S) load balancers that are in either Premium Tier or Standard Tier. You can use security policies with GKE and the default Ingress controller.
NEW QUESTION # 46
You are disabling DNSSEC for one of your Cloud DNS-managed zones. You removed the DS records from your zone file, waited for them to expire from the cache, and disabled DNSSEC for the zone. You receive reports that DNSSEC validating resolves are unable to resolve names in your zone.
What should you do?
- A. Set the zone to the TRANSFER state.
- B. Update the TTL for the zone.
- C. Transfer ownership of the domain to a new registar.
- D. Disable DNSSEC at your domain registar.
Answer: D
Explanation:
Before disabling DNSSEC for a managed zone you want to use, you must deactivate DNSSEC at your domain registrar to ensure that DNSSEC-validating resolvers can still resolve names in the zone.
https://cloud.google.com/dns/docs/dnssec-config
NEW QUESTION # 47
You need to restrict access to your Google Cloud load-balanced application so that only specific IP addresses can connect.
What should you do?
- A. Label the backend instances "application," and create a firewall rule with the target label "application" and the source IP range of the allowed clients and Google health check IP ranges.
- B. Tag the backend instances "application," and create a firewall rule with target tag "application" and the source IP range of the allowed clients and Google health check IP ranges.
- C. Create a secure perimeter using the Access Context Manager feature of VPC Service Controls and restrict access to the source IP range of the allowed clients and Google health check IP ranges.
- D. Create a secure perimeter using VPC Service Controls, and mark the load balancer as a service restricted to the source IP range of the allowed clients and Google health check IP ranges.
Answer: B
Explanation:
https://link.springer.com/chapter/10.1007/978-1-4842-1004-8_4
NEW QUESTION # 48
You created a new VPC network named Dev with a single subnet. You added a firewall rule for the network Dev to allow HTTP traffic only and enabled logging. When you try to log in to an instance in the subnet via Remote Desktop Protocol, the login fails. You look for the Firewall rules logs in Stackdriver Logging, but you do not see any entries for blocked traffic. You want to see the logs for blocked traffic.
What should you do?
- A. Check the VPC flow logs for the instance.
- B. Try connecting to the instance via SSH, and check the logs.
- C. Create a new firewall rule with priority 65500 to deny all traffic, and enable logs.
- D. Create a new firewall rule to allow traffic from port 22, and enable logs.
Answer: C
Explanation:
Ingress packets in VPC Flow Logs are sampled after ingress firewall rules. If an ingress firewall rule denies inbound packets, those packets are not sampled by VPC Flow Logs. We want to see the logs for blocked traffic so we have to look for them in firewall logs. https://cloud.google.com/vpc/docs/flow-logs#key_properties
NEW QUESTION # 49
You want to create a service in GCP using IPv6.
What should you do?
- A. Configure a global load balancer with the designated IPv6 address.
- B. Configure a TCP Proxy with the designated IPv6 address.
- C. Create the instance with the designated IPv6 address.
- D. Configure an internal load balancer with the designated IPv6 address.
Answer: A
NEW QUESTION # 50
You are designing a shared VPC architecture. Your network and security team has strict controls over which routes are exposed between departments. Your Production and Staging departments can communicate with each other, but only via specific networks. You want to follow Google-recommended practices.
How should you design this topology?
- A. Create 2 shared VPCs within the shared VPC Service Project, and create a Cloud VPN/Cloud Router between them. Use Flexible Route Advertisement (FRA) to filter access between the specific networks.
- B. Create 2 shared VPCs within the shared VPC Host Project, and enable VPC peering between them. Use firewall rules to filter access between the specific networks.
- C. Create 1 VPC within the shared VPC Host Project, and share individual subnets with the Service Projects to filter access between the specific networks.
- D. Create 2 shared VPCs within the shared VPC Host Project, and create a Cloud VPN/Cloud Router between them. Use Flexible Route Advertisement (FRA) to filter access between the specific networks.
Answer: C
NEW QUESTION # 51
You are trying to update firewall rules in a shared VPC for which you have been assigned only Network Admin permissions. You cannot modify the firewall rules. Your organization requires using the least privilege necessary.
Which level of permissions should you request?
- A. Service Project Admin privileges from the Shared VPC Admin.
- B. Organization Admin privileges from the Organization Admin.
- C. Security Admin privileges from the Shared VPC Admin.
- D. Shared VPC Admin privileges from the Organization Admin.
Answer: C
Explanation:
Explanation/Reference: https://cloud.google.com/vpc/docs/shared-vpc
NEW QUESTION # 52
You are designing a Partner Interconnect hybrid cloud connectivity solution with geo-redundancy across two metropolitan areas. You want to follow Google-recommended practices to set up the following region/metro pairs:
(region 1/metro 1)
(region 2/metro 2)
What should you do?
- A. Create a Cloud Router in region 1 with one VLAN attachment connected to metro1-zone2-x.
Create a Cloud Router in region 2 with one VLAN attachment connected to metro2-zone2-x. - B. Create a Cloud Router in region 1 with two VLAN attachments connected to metro1-zone1-x.
Create a Cloud Router in region 2 with two VLAN attachments connected to metro1-zone2-x. - C. Create a Cloud Router in region 1 with one VLAN attachment connected to metro1-zone1-x.
Create a Cloud Router in region 2 with two VLAN attachments connected to metro2-zone2-x. - D. Create a Cloud Router in region 1 with one VLAN attachment connected to metro1-zone1-x and one VLAN attachment connected to metro1-zone2-x.
Create a Cloud Router in region 2 with one VLAN attachment connected to metro2-zone1-x and one VLAN attachment to metro2-zone2-x.
Answer: C
NEW QUESTION # 53
You are increasing your usage of Cloud VPN between on-premises and GCP, and you want to support more traffic than a single tunnel can handle. You want to increase the available bandwidth using Cloud VPN.
What should you do?
- A. Create two VPN tunnels on the same Cloud VPN gateway that point to the same destination VPN gateway IP address.
- B. Add a second on-premises VPN gateway with a different public IP address. Create a second tunnel on the existing Cloud VPN gateway that forwards the same IP range, but points at the new on-premises gateway IP.
- C. Double the MTU on your on-premises VPN gateway from 1460 bytes to 2920 bytes.
- D. Add a second Cloud VPN gateway in a different region than the existing VPN gateway. Create a new tunnel on the second Cloud VPN gateway that forwards the same IP range, but points to the existing on-premises VPN gateway IP address.
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION # 54
You are designing a hybrid cloud environment for your organization. Your Google Cloud environment is interconnected with your on-premises network using Cloud HA VPN and Cloud Router. The Cloud Router is configured with the default settings. Your on-premises DNS server is located at 192.168.20.88 and is protected by a firewall, and your Compute Engine resources are located at 10.204.0.0/24. Your Compute Engine resources need to resolve on-premises private hostnames using the domain corp.altostrat.com while still resolving Google Cloud hostnames. You want to follow Google-recommended practices. What should you do?
- A. Create a private zone in Cloud DNS for 'corp altostrat.com' called corp-altostrat-com.
Configure DNS Server Policies and create a policy with Alternate DNS servers to 192.168.20.88.
Configure your on-premises firewall to accept traffic from 35.199.192.0/19. - B. Create a private forwarding zone in Cloud DNS for 'corp.altostrat.com' called corp-altostrat-com that points to 192.168 20.88.
Configure your on-premises firewall to accept traffic from 35.199.192.0/19 Set a custom route advertisement on the Cloud Router for 35.199.192.0/19. - C. Create a private forwarding zone in Cloud DNS for 'corp.altostrat.com' called corp-altostrat-com that points to 192.168.20.88.
Configure your on-premises firewall to accept traffic from 10.204.0.0/24.
Set a custom route advertisement on the Cloud Router for 10.204.0.0/24 - D. Create a private forwarding zone in Cloud DNS for 'corp .altostrat.com' called corp-altostrat-com that points to 192.168.20.88.
Configure your on-premises firewall to accept traffic from 10.204.0.0/24.
Modify the /etc/resolv conf file on your Compute Engine instances to point to 192.168.20 88
Answer: A
Explanation:
Set a custom route advertisement on the Cloud Router for 35.199.192.0/19.
NEW QUESTION # 55
Your company is working with a partner to provide a solution for a customer. Both your company and the partner organization are using GCP. There are applications in the partner's network that need access to some resources in your company's VPC. There is no CIDR overlap between the VPCs.
Which two solutions can you implement to achieve the desired results without compromising the security? (Choose two.)
- A. Cloud VPN
- B. VPC peering
- C. Dedicated Interconnect
- D. Cloud NAT
- E. Shared VPC
Answer: A,B
Explanation:
Google Cloud VPC Network Peering allows internal IP address connectivity across two Virtual Private Cloud (VPC) networks regardless of whether they belong to the same project or the same organization.
NEW QUESTION # 56
You need to establish network connectivity between three Virtual Private Cloud networks, Sales, Marketing, and Finance, so that users can access resources in all three VPCs. You configure VPC peering between the Sales VPC and the Finance VPC. You also configure VPC peering between the Marketing VPC and the Finance VPC. After you complete the configuration, some users cannot connect to resources in the Sales VPC and the Marketing VPC. You want to resolve the problem.
What should you do?
- A. Delete the legacy network and recreate it to allow transitive peering.
- B. Create network tags to allow connectivity between all three VPCs.
- C. Alter the routing table to resolve the asymmetric route.
- D. Configure VPC peering in a full mesh.
Answer: D
Explanation:
https://cloud.google.com/vpc/docs/using-vpc-peering
NEW QUESTION # 57
All the instances in your project are configured with the custom metadata enable-oslogin value set to FALSE and to block project-wide SSH keys. None of the instances are set with any SSH key, and no project-wide SSH keys have been configured. Firewall rules are set up to allow SSH sessions from any IP address range. You want to SSH into one instance.
What should you do?
- A. Open the Cloud Shell SSH into the instance using gcloud compute ssh.
- B. Generate a new SSH key pair. Verify the format of the private key and add it to the instance.
SSH into the instance using a third-party tool like putty or ssh. - C. Generate a new SSH key pair. Verify the format of the public key and add it to the project.
SSH into the instance using a third-party tool like putty or ssh. - D. Set the custom metadata enable-oslogin to TRUE, and SSH into the instance using a third-party tool like putty or ssh.
Answer: D
Explanation:
https://cloud.google.com/compute/docs/storing-retrieving-metadata
NEW QUESTION # 58
You recently deployed Cloud VPN to connect your on-premises data canter to Google Cloud. You need to monitor the usage of this VPN and set up alerts in case traffic exceeds the maximum allowed. You need to be able to quickly decide whether to add extra links or move to a Dedicated Interconnect. What should you do?
- A. In the Monitoring section of the Google Cloud Console, use the Dashboard section to select a default dashboard for VPN usage.
- B. In the Network Intelligence Canter, check for the number of packet drops on the VPN.
- C. In the Google Cloud Console, use Monitoring Query Language to create a custom alert for bandwidth utilization.
- D. In the VPN section of the Google Cloud Console, select the VPN under hybrid connectivity, and then select monitoring to display utilization on the dashboard.
Answer: B
NEW QUESTION # 59
You want to apply a new Cloud Armor policy to an application that is deployed in Google Kubernetes Engine (GKE). You want to find out which target to use for your Cloud Armor policy.
Which GKE resource should you use?
- A. GKE Ingress
- B. GKE Node
- C. GKE Pod
- D. GKE Cluster
Answer: C
NEW QUESTION # 60
You have a Cloud Storage bucket in Google Cloud project XYZ. The bucket contains sensitive dat a. You need to design a solution to ensure that only instances belonging to VPCs under project XYZ can access the data stored in this Cloud Storage bucket. What should you do?
- A. Configure Private Google Access to privately access the Cloud Storage service using private IP addresses.
- B. Configure a VPC Service Controls perimeter around project XYZ, and include storage.googleapis.com as a restricted service in the service perimeter.
- C. Configure Private Service Connect to privately access Cloud Storage from all VPCs under project XYZ.
- D. Configure Cloud Storage with projectPrivate Access Control List (ACL) that gives permission to the project team based on their roles.
Answer: D
NEW QUESTION # 61
You need to enable Cloud CDN for all the objects inside a storage bucket. You want to ensure that all the objects in the storage bucket can be served by the CDN.
What should you do in the GCP Console?
- A. Create a new cloud storage bucket, and then enable Cloud CDN on it.
- B. Create a new HTTP load balancer, select the storage bucket as a backend, enable Cloud CDN on the backend, and make sure each object inside the storage bucket is shared publicly.
- C. Create a new SSL proxy load balancer, select the storage bucket as a backend, and then enable Cloud CDN on the backend.
- D. Create a new TCP load balancer, select the storage bucket as a backend, and then enable Cloud CDN on the backend.
Answer: A
NEW QUESTION # 62
You work for a multinational enterprise that is moving to GCP.
These are the cloud requirements:
* An on-premises data center located in the United States in Oregon and New York with Dedicated Interconnects connected to Cloud regions us-west1 (primary HQ) and us-east4 (backup)
* Multiple regional offices in Europe and APAC
* Regional data processing is required in europe-west1 and australia-southeast1
* Centralized Network Administration Team
Your security and compliance team requires a virtual inline security appliance to perform L7 inspection for URL filtering. You want to deploy the appliance in us-west1.
What should you do?
- A. * Create 2 VPCs in a Shared VPC Host Project.* Configure a 2-NIC instance in zone us-west1-a in the Service Project.* Attach NIC0 in VPC #1 us-west1 subnet of the Host Project.* Attach NIC1 in VPC #2 us-west1 subnet of the Host Project.* Deploy the instance.* Configure the necessary routes and firewall rules to pass traffic through the instance.
- B. * Create 1 VPC in a Shared VPC Host Project.* Configure a 2-NIC instance in zone us-west1-a in the Host Project.* Attach NIC0 in us-west1 subnet of the Host Project.* Attach NIC1 in us-west1 subnet of the Host Project* Deploy the instance.* Configure the necessary routes and firewall rules to pass traffic through the instance.
- C. * Create 2 VPCs in a Shared VPC Host Project.* Configure a 2-NIC instance in zone us-west1-a in the Host Project.* Attach NIC0 in VPC #1 us-west1 subnet of the Host Project.* Attach NIC1 in VPC #2 us-west1 subnet of the Host Project.* Deploy the instance.* Configure the necessary routes and firewall rules to pass traffic through the instance.
- D. * Create 1 VPC in a Shared VPC Service Project.* Configure a 2-NIC instance in zone us-west1-a in the Service Project.* Attach NIC0 in us-west1 subnet of the Service Project.* Attach NIC1 in us-west1 subnet of the Service Project* Deploy the instance.* Configure the necessary routes and firewall rules to pass traffic through the instance.
Answer: C
NEW QUESTION # 63
Your on-premises data center has 2 routers connected to your Google Cloud environment through a VPN on each router. All applications are working correctly; however, all of the traffic is passing across a single VPN instead of being load-balanced across the 2 connections as desired.
During troubleshooting you find:
* Each on-premises router is configured with a unique ASN.
* Each on-premises router is configured with the same routes and priorities.
* Both on-premises routers are configured with a VPN connected to a single Cloud Router.
* BGP sessions are established between both on-premises routers and the Cloud Router.
* Only 1 of the on-premises router's routes are being added to the routing table.
What is the most likely cause of this problem?
- A. The ASNs being used on the on-premises routers are different.
- B. A firewall is blocking the traffic across the second VPN connection.
- C. The on-premises routers are configured with the same routes.
- D. You do not have a load balancer to load-balance the network traffic.
Answer: D
NEW QUESTION # 64
Your organization is deploying a single project for 3 separate departments. Two of these departments require network connectivity between each other, but the third department should remain in isolation. Your design should create separate network administrative domains between these departments. You want to minimize operational overhead.
How should you design the topology?
- A. Create 3 separate VPCs, and use VPC peering to establish connectivity between the two appropriate VPCs.
- B. Create a single project, and deploy specific firewall rules. Use network tags to isolate access between the departments.
- C. Create 3 separate VPCs, and use Cloud VPN to establish connectivity between the two appropriate VPCs.
- D. Create a Shared VPC Host Project and the respective Service Projects for each of the 3 separate departments.
Answer: D
Explanation:
Use Shared VPC to connect to a common VPC network. Resources in those projects can communicate with each other securely and efficiently across project boundaries using internal IPs. You can manage shared network resources, such as subnets, routes, and firewalls, from a central host project, enabling you to apply and enforce consistent network policies across the projects.
With Shared VPC and IAM controls, you can separate network administration from project administration. This separation helps you implement the principle of least privilege. For example, a centralized network team can administer the network without having any permissions into the participating projects. Similarly, the project admins can manage their project resources without any permissions to manipulate the shared network.
NEW QUESTION # 65
You have created an HTTP(S) load balanced service. You need to verify that your backend instances are responding properly.
How should you configure the health check?
- A. Set proxy-header to the default value, and set host to include a custom host header that identifies the health check.
- B. Set request-path to a specific URL used for health checking, and set response to a string that the backend service will always return in the response body.
- C. Set request-path to a specific URL used for health checking, and set host to include a custom host header that identifies the health check.
- D. Set request-path to a specific URL used for health checking, and set proxy-header to PROXY_V1.
Answer: B
Explanation:
https://cloud.google.com/load-balancing/docs/health-check-concepts#content-based_health_checks
NEW QUESTION # 66
......
How much Google Professional Cloud Network Engineer Exam cost
Google Professional Cloud Network Engineer exam cost is $200 USD.
Google Professional-Cloud-Network-Engineer Exam is an industry-recognized certification that demonstrates your expertise in network infrastructure on the Google Cloud Platform. By earning this certification, you can prove your worth to potential employers and clients. Professional-Cloud-Network-Engineer exam is an excellent way to enhance your career prospects and increase your earning potential. Moreover, it is a testament to your dedication to your profession and your willingness to adapt to new technologies.
Powerful Professional-Cloud-Network-Engineer PDF Dumps for Professional-Cloud-Network-Engineer Questions: https://torrentvce.exam4free.com/Professional-Cloud-Network-Engineer-valid-dumps.html
