DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Latest Google Professional Cloud Network Engineer Exam Questions for Comprehensive Preparation

SPOTO's Google Professional Cloud Network Engineer exam questions provide a valuable advantage for individuals pursuing expertise in implementing and managing network architectures in Google Cloud. With a focus on exam questions and answers, test questions, and mock exams, SPOTO offers a comprehensive platform for effective exam preparation. As a Professional Cloud Network Engineer, candidates gain hands-on experience with network services, application networking, hybrid and multi-cloud connectivity, VPC implementation, and network security on Google Cloud. SPOTO's study materials cover key concepts and best practices, empowering candidates to navigate the Google Cloud Console and command-line interface with confidence. By leveraging SPOTO's exam resources, candidates can enhance their skills and knowledge, increasing their chances of passing the exam successfully and contributing to successful cloud implementations in real-world scenarios.
Take other online exams

Question #1
Your company's web server administrator is migrating on-premises backend servers for an application to GCP. Libraries and configurations differ significantly across these backend servers. The migration to GCP will be lift- and-shift, and all requests to the servers will be served by a single network load balancer frontend. You want to use a GCP-native solution when possible.How should you deploy this service in GCP?
A. Create a managed instance group from one of the images of the on-premises servers, and link this instance group to a target pool behind your load balancer
B. Create a target pool, add all backend instances to this target pool, and deploy the target pool behind your load balancer
C. Deploy a third-party virtual appliance as frontend to these servers that will accommodate the significant differences between these backend servers
D. Use GCP's ECMP capability to load-balance traffic to the backend servers by installing multiple equal- priority static routes to the backend servers
View answer
Correct Answer: B
Question #2
You decide to set up Cloud NAT. After completing the configuration, you find that one of your instances is not using the Cloud NAT for outbound NAT.What is the most likely cause of this problem?
A. The instance has been configured with multiple interfaces
B. An external IP address has been configured on the instance
C. You have created static routes that use RFC1918 ranges
D. The instance is accessible by a load balancer external IP address
View answer
Correct Answer: B
Question #3
You want to create a service in GCP using IPv6. What should you do?
A. Create the instance with the designated IPv6 address
B. Configure a TCP Proxy with the designated IPv6 address
C. Configure a global load balancer with the designated IPv6 address
D. Configure an internal load balancer with the designated IPv6 address
View answer
Correct Answer: B
Question #4
Your company has recently expanded their EMEA-based operations into APAC. Globally distributed users report that their SMTP and IMAP services are slow. Your company requires end-to-end encryption, but you do not have access to the SSL certificates.Which Google Cloud load balancer should you use?
A. SSL proxy load balancer
B. Network load balancer
C. HTTPS load balancer
D. TCP proxy load balancer
View answer
Correct Answer: A
Question #5
Your company is working with a partner to provide a solution for a customer. Both your company and the partner organization are using GCP. There are applications in the partner's network that need access to some resources in your company's VPC. There is no CIDR overlap between the VPCs.Which two solutions can you implement to achieve the desired results without compromising the security? (Choose two.)
A. Add an appropriate lifecycle rule on the storage bucket
B. Issue a cache invalidation command with pattern /folder-a/*
C. Make sure that all the objects with prefix folder-a are not shared publicly
D. Disable Cloud CDN on the storage bucket
View answer
Correct Answer: CD
Question #6
You created a new VPC for your development team. You want to allow access to the resources in this VPC via SSH only.How should you configure your firewall rules?
A. Create two firewall rules: one to block all traffic with priority 0, and another to allow port 22 with priority 1000
B. Create two firewall rules: one to block all traffic with priority 65536, and another to allow port 3389 with priority 1000
C. Create a single firewall rule to allow port 22 with priority 1000
D. Create a single firewall rule to allow port 3389 with priority 1000
View answer
Correct Answer: C
Question #7
You want to create a service in GCP using IPv6. What should you do?
A. Create the instance with the designated IPv6 address
B. Configure a TCP Proxy with the designated IPv6 address
C. Configure a global load balancer with the designated IPv6 address
D. Configure an internal load balancer with the designated IPv6 address
View answer
Correct Answer: B
Question #8
You need to establish network connectivity between three Virtual Private Cloud networks, Sales, Marketing, and Finance, so that users can access resources in all three VPCs. You configure VPC peering between the Sales VPC and the Finance VPC. You also configure VPC peering between the Marketing VPC and the Finance VPC. After you complete the configuration, some users cannot connect to resources in the Sales VPC and the Marketing VPC. You want to resolve the problem.What should you do?
A. HTTP(S) load balancer
B. SSL proxy load balancer
C. TCP proxy load balancer
D. Network load balancer
View answer
Correct Answer: A
Question #9
Your organization is deploying a single project for 3 separate departments. Two of these departments require network connectivity between each other, but the third department should remain in isolation. Your design should create separate network administrative domains between these departments. You want to minimize operational overhead. How should you design the topology?
A. Create a Shared VPC Host Project and the respective Service Projects for each of the 3 separate departments
B. Create 3 separate VPCs, and use Cloud VPN to establish connectivity between the two appropriate VPCs
C. Create 3 separate VPCs, and use VPC peering to establish connectivity between the two appropriate VPCs
D. Create a single project, and deploy specific firewall rules
View answer
Correct Answer: A
Question #10
You converted an auto mode VPC network to custom mode. Since the conversion, some of your Cloud Deployment Manager templates are no longer working. You want to resolve the problem.What should you do?
A. Apply an additional IAM role to the Google API’s service account to allow custom mode networks
B. Update the VPC firewall to allow the Cloud Deployment Manager to access the custom mode networks
C. Explicitly reference the custom mode networks in the Cloud Armor whitelist
D. Explicitly reference the custom mode networks in the Deployment Manager templates
View answer
Correct Answer: D
Question #11
Your on-premises data center has 2 routers connected to your GCP through a VPN on each router. All applications are working correctly; however, all of the traffic is passing across a single VPN instead of being load-balanced across the 2 connections as desired.During troubleshooting you find:"¢ Each on-premises router is configured with the same ASN."¢ Each on-premises router is configured with the same routes and priorities."¢ Both on-premises routers are configured with a VPN connected to a single Cloud R
A. One of the VPN sessions is configured incorrectly
B. A firewall is blocking the traffic across the second VPN connection
C. You do not have a load balancer to load-balance the network traffic
D. BGP sessions are not established between both on-premises routers and the Cloud Router
View answer
Correct Answer: C
Question #12
You created a VPC network named Retail in auto mode. You want to create a VPC network named Distribution and peer it with the Retail VPC.How should you configure the Distribution VPC?
A. Create the Distribution VPC in auto mode
B. Create the Distribution VPC in custom mode
C. Create the Distribution VPC in custom mode
D. Rename the default VPC as "Distribution" and peer it via network peering
View answer
Correct Answer: B
Question #13
You have recently been put in charge of managing identity and access management for your organization. You have several projects and want to use scripting and automation wherever possible. You want to grant the editor role to a project member.Which two methods can you use to accomplish this? (Choose two.)
A. Tune TCP parameters on the on-premises servers
B. Compress files using utilities like tar to reduce the size of data being sent
C. Remove the -m flag from the gsutil command to enable single-threaded transfers
D. Use the perfdiag parameter in your gsutil command to enable faster performance: gsutil perfdiag gs://[BUCKET NAME]
View answer
Correct Answer: DE
Question #14
You decide to set up Cloud NAT. After completing the configuration, you find that one of your instances is not using the Cloud NAT for outbound NAT.What is the most likely cause of this problem?
A. The instance has been configured with multiple interfaces
B. An external IP address has been configured on the instance
C. You have created static routes that use RFC1918 ranges
D. The instance is accessible by a load balancer external IP address
View answer
Correct Answer: B
Question #15
You have a web application that is currently hosted in the us-central1 region. Users experience high latency when traveling in Asia. You've configured a network load balancer, but users have not experienced a performance improvement. You want to decrease the latency.What should you do?
A. Configure a policy-based route rule to prioritize the traffic
B. Configure an HTTP load balancer, and direct the traffic to it
C. Configure Dynamic Routing for the subnet hosting the application
D. Configure the TTL for the DNS zone to decrease the time between updates
View answer
Correct Answer: B
Question #16
You need to restrict access to your Google Cloud load-balanced application so that only specific IP addresses can connect.What should you do?
A. Create a secure perimeter using the Access Context Manager feature of VPC Service Controls and restrict access to the source IP range of the allowed clients and Google health check IP ranges
B. Create a secure perimeter using VPC Service Controls, and mark the load balancer as a service restricted to the source IP range of the allowed clients and Google health check IP ranges
C. Tag the backend instances "application," and create a firewall rule with target tag "application" and the source IP range of the allowed clients and Google health check IP ranges
D. Label the backend instances "application," and create a firewall rule with the target label "application" and the source IP range of the allowed clients and Google health check IP ranges
View answer
Correct Answer: C
Question #17
You have configured Cloud CDN using HTTP(S) load balancing as the origin for cacheable content. Compression is configured on the web servers, but responses served by Cloud CDN are not compressed.What is the most likely cause of the problem?
A. You have not configured compression in Cloud CDN
B. You have configured the web servers and Cloud CDN with different compression types
C. The web servers behind the load balancer are configured with different compression types
D. You have to configure the web servers to compress responses even if the request has a Via header
View answer
Correct Answer: D
Question #18
You have deployed a new internal application that provides HTTP and TFTP services to on-premises hosts. You want to be able to distribute traffic across multiple Compute Engine instances, but need to ensure that clients are sticky to a particular instance across both services.Which session affinity should you choose?
A. None
B. Client IP
C. Client IP and protocol
D. Client IP, port and protocol
View answer
Correct Answer: B
Question #19
You have an application running on Compute Engine that uses BigQuery to generate some results that are stored in Cloud Storage. You want to ensure that none of the application instances have external IP addresses. Which two methods can you use to accomplish this? (Choose two.)
A. Create 2 shared VPCs within the shared VPC Host Project, and enable VPC peering between them
B. Create 2 shared VPCs within the shared VPC Host Project, and create a Cloud VPN/Cloud Router between them
C. Create 2 shared VPCs within the shared VPC Service Project, and create a Cloud VPN/Cloud Router between them
D. Create 1 VPC within the shared VPC Host Project, and share individual subnets with the Service Projects to filter access between the specific networks
View answer
Correct Answer: BE
Question #20
Your company just completed the acquisition of Altostrat (a current GCP customer). Each company has a separate organization in GCP and has implemented a custom DNS solution. Each organization will retain its current domain and host names until after a full transition and architectural review is done in one year. These are the assumptions for both GCP environments.•Each organization has enabled full connectivity between all of its projects by using Shared VPC.•Both organizations strictly use the 10.0.0.0/8 a
A. The on-premises routers are configured with the same routes
B. A firewall is blocking the traffic across the second VPN connection
C. You do not have a load balancer to load-balance the network traffic
D. The ASNs being used on the on-premises routers are different
View answer
Correct Answer: CD
Question #21
You are trying to update firewall rules in a shared VPC for which you have been assigned only Network Admin permissions. You cannot modify the firewall rules. Your organization requires using the least privilege necessary.Which level of permissions should you request?
A. Security Admin privileges from the Shared VPC Admin
B. Service Project Admin privileges from the Shared VPC Admin
C. Shared VPC Admin privileges from the Organization Admin
D. Organization Admin privileges from the Organization Admin
View answer
Correct Answer: A
Question #22
You are migrating to Cloud DNS and want to import your BIND zone file. Which command should you use?
A. gcloud dns record-sets import ZONE_FILE --zone MANAGED_ZONE
B. gcloud dns record-sets import ZONE_FILE --replace-origin-ns --zone MANAGED_ZONE
C. gcloud dns record-sets import ZONE_FILE --zone-file-format --zone MANAGED_ZONE
D. gcloud dns record-sets import ZONE_FILE --delete-all-existing --zone MANAGED ZONE
View answer
Correct Answer: C
Question #23
You have configured Cloud CDN using HTTP(S) load balancing as the origin for cacheable content. Compression is configured on the web servers, but responses served by Cloud CDN are not compressed.What is the most likely cause of the problem?
A. You have not configured compression in Cloud CDN
B. You have configured the web servers and Cloud CDN with different compression types
C. The web servers behind the load balancer are configured with different compression types
D. You have to configure the web servers to compress responses even if the request has a Via header
View answer
Correct Answer: D
Question #24
You need to restrict access to your Google Cloud load-balanced application so that only specific IP addresses can connect.What should you do?
A. reate a secure perimeter using the Access Context Manager feature of VPC Service Controls and restrict access to the source IP range of the allowed clients and Google health check IP ranges
B. reate a secure perimeter using VPC Service Controls, and mark the load balancer as a service restricted to the source IP range of the allowed clients and Google health check IP ranges
C. ag the backend instances "application," and create a firewall rule with target tag "application" and the source IP range of the allowed clients and Google health check IP ranges
D. abel the backend instances "application," and create a firewall rule with the target label "application" and the source IP range of the allowed clients and Google health check IP ranges
View answer
Correct Answer: C
Question #25
Your company offers a popular gaming service. Your instances are deployed with private IP addresses, and external access is granted through a global load balancer. You believe you have identified a potential malicious actor, but aren't certain you have the correct client IP address. You want to identify this actor while minimizing disruption to your legitimate users.What should you do?
A. Create a Cloud Armor Policy rule that denies traffic and review necessary logs
B. Create a Cloud Armor Policy rule that denies traffic, enable preview mode, and review necessary logs
C. Create a VPC Firewall rule that denies traffic, enable logging and set enforcement to disabled, and review necessary logs
D. Create a VPC Firewall rule that denies traffic, enable logging and set enforcement to enabled, and review necessary logs
View answer
Correct Answer: D
Question #26
You converted an auto mode VPC network to custom mode. Since the conversion, some of your Cloud Deployment Manager templates are no longer working. You want to resolve the problem.What should you do?
A. Apply an additional IAM role to the Google API’s service account to allow custom mode networks
B. Update the VPC firewall to allow the Cloud Deployment Manager to access the custom mode networks
C. Explicitly reference the custom mode networks in the Cloud Armor whitelist
D. Explicitly reference the custom mode networks in the Deployment Manager templates
View answer
Correct Answer: D
Question #27
You have deployed a new internal application that provides HTTP and TFTP services to on-premises hosts. You want to be able to distribute traffic across multiple Compute Engine instances, but need to ensure that clients are sticky to a particular instance across both services.Which session affinity should you choose?
A. None
B. Client IP
C. Client IP and protocol
D. Client IP, port and protocol
View answer
Correct Answer: B
Question #28
You want to set up two Cloud Routers so that one has an active Border Gateway Protocol (BGP) session, and the other one acts as a standby.Which BGP attribute should you use on your on-premises router?
A. AS-Path
B. Community
C. Local Preference
D. Multi-exit Discriminator
View answer
Correct Answer: D
Question #29
You are designing a Google Kubernetes Engine (GKE) cluster for your organization. The current cluster size is expected to host 10 nodes, with 20 Pods per node and 150 services. Because of the migration of new services over the next 2 years, there is a planned growth for 100 nodes, 200 Pods per node, and 1500 services. You want to use VPC-native clusters with alias IP ranges, while minimizing address consumption.How should you design this topology?
A. Create a subnet of size/25 with 2 secondary ranges of: /17 for Pods and /21 for Services
B. Create a subnet of size/28 with 2 secondary ranges of: /24 for Pods and /24 for Services
C. Use gcloud container clusters create [CLUSTER NAME]--enable-ip-alias to create a VPC-native cluster
D. Use gcloud container clusters create [CLUSTER NAME] to create a VPC-native cluster
View answer
Correct Answer: B
Question #30
Your company is running out of network capacity to run a critical application in the on-premises data center. You want to migrate the application to GCP. You also want to ensure that the Security team does not lose their ability to monitor traffic to and from Compute Engine instances.Which two products should you incorporate into the solution? (Choose two.)
A. GKE Node
B. GKE Pod
C. GKE Cluster
D. GKE Ingress
View answer
Correct Answer: CD
Question #31
You need to centralize the Identity and Access Management permissions and email distribution for the WebServices Team as efficiently as possible.What should you do?
A. Create a Google Group for the WebServices Team
B. Create a G Suite Domain for the WebServices Team
C. Create a new Cloud Identity Domain for the WebServices Team
D. Create a new Custom Role for all members of the WebServices Team
View answer
Correct Answer: A
Question #32
Your organization is deploying a single project for 3 separate departments. Two of these departments require network connectivity between each other, but the third department should remain in isolation. Your design should create separate network administrative domains between these departments. You want to minimize operational overhead.How should you design the topology?
A. reate a Shared VPC Host Project and the respective Service Projects for each of the 3 separate departments
B. reate 3 separate VPCs, and use Cloud VPN to establish connectivity between the two appropriate VPCs
C. reate 3 separate VPCs, and use VPC peering to establish connectivity between the two appropriate VPCs
D. reate a single project, and deploy specific firewall rules
View answer
Correct Answer: A
Question #33
You are using the gcloud command line tool to create a new custom role in a project by coping a predefined role. You receive this error message:INVALID_ARGUMENT: Permission resourcemanager.projects.list is not validWhat should you do?
A. Add the resourcemanager
B. Try again with a different role with a new name but the same permissions
C. Remove the resourcemanager
D. Add the resourcemanager
View answer
Correct Answer: C
Question #34
You need to define an address plan for a future new GKE cluster in your VPC. This will be a VPC native cluster, and the default Pod IP range allocation will be used. You must pre-provision all the needed VPC subnets and their respective IP address ranges before cluster creation. The cluster will initially have a single node, but it will be scaled to a maximum of three nodes if necessary. You want to allocate the minimum number of Pod IP addresses.Which subnet mask should you use for the Pod IP address range
A. /21
B. /22
C. /23
D. /25
View answer
Correct Answer: D
Question #35
You are using a 10-Gbps direct peering connection to Google together with the gsutil tool to upload files to Cloud Storage buckets from on-premises servers. The on-premises servers are 100 milliseconds away from the Google peering point. You notice that your uploads are not using the full 10-Gbps bandwidth available to you. You want to optimize the bandwidth utilization of the connection.What should you do on your on-premises servers?
A. • Create 2 VPCs in a Shared VPC Host Project
B. • Create 2 VPCs in a Shared VPC Host Project
C. • Create 1 VPC in a Shared VPC Host Project
D. • Create 1 VPC in a Shared VPC Service Project
View answer
Correct Answer: A
Question #36
All the instances in your project are configured with the custom metadata enable-oslogin value set to FALSE and to block project-wide SSH keys. None of the instances are set with any SSH key, and no project- wide SSH keys have been configured. Firewall rules are set up to allow SSH sessions from any IP address range. You want to SSH into one instance.What should you do?
A. Use Shared VPC, and deploy the VLAN attachments and Interconnect in the host project
B. Use Shared VPC, and deploy the VLAN attachments in the service projects
C. Use standalone projects, and deploy the VLAN attachments in the individual projects
D. Use standalone projects and deploy the VLAN attachments and Interconnects in each of the individual projects
View answer
Correct Answer: B
Question #37
You have recently been put in charge of managing identity and access management for your organization. You have several projects and want to use scripting and automation wherever possible. You want to grant the editor role to a project member.Which two methods can you use to accomplish this? (Choose two.)
A. Tune TCP parameters on the on-premises servers
B. Compress files using utilities like tar to reduce the size of data being sent
C. Remove the -m flag from the gsutil command to enable single-threaded transfers
D. Use the perfdiag parameter in your gsutil command to enable faster performance: gsutil perfdiag gs://[BUCKET NAME]
View answer
Correct Answer: DE
Question #38
Your company just completed the acquisition of Altostrat (a current GCP customer). Each company has a separate organization in GCP and has implemented a custom DNS solution. Each organization will retain its current domain and host names until after a full transition and architectural review is done in one year. These are the assumptions for both GCP environments.•Each organization has enabled full connectivity between all of its projects by using Shared VPC.•Both organizations strictly use the 10.0.0.0/8 a
A. The on-premises routers are configured with the same routes
B. A firewall is blocking the traffic across the second VPN connection
C. You do not have a load balancer to load-balance the network traffic
D. The ASNs being used on the on-premises routers are different
View answer
Correct Answer: CD
Question #39
You are increasing your usage of Cloud VPN between on-premises and GCP, and you want to support more traffic than a single tunnel can handle. You want to increase the available bandwidth using Cloud VPN.What should you do?
A. Double the MTU on your on-premises VPN gateway from 1460 bytes to 2920 bytes
B. Create two VPN tunnels on the same Cloud VPN gateway that point to the same destination VPN gateway IP address
C. Add a second on-premises VPN gateway with a different public IP address
D. Add a second Cloud VPN gateway in a different region than the existing VPN gateway
View answer
Correct Answer: C
Question #40
Your end users are located in close proximity to us-east1 and europe-west1. Their workloads need to communicate with each other. You want to minimize cost and increase network efficiency.How should you design this topology?
A. Create 2 VPCs, each with their own regions and individual subnets
B. Create 2 VPCs, each with their own region and individual subnets
C. Create 1 VPC with 2 regional subnets
D. Create 1 VPC with 2 regional subnets
View answer
Correct Answer: D
Question #41
You have an application hosted on a Compute Engine virtual machine instance that cannot communicate with a resource outside of its subnet. When you review the flow and firewall logs, you do not see any denied traffic listed.During troubleshooting you find:•Flow logs are enabled for the VPC subnet, and all firewall rules are set to log.•The subnetwork logs are not excluded from Stackdriver.•The instance that is hosting the application can communicate outside the subnet.•Other instances within the subnet can
A. The traffic is matching the expected ingress rule
B. The traffic is matching the expected egress rule
C. The traffic is not matching the expected ingress rule
D. The traffic is not matching the expected egress rule
View answer
Correct Answer: C
Question #42
You have created a firewall with rules that only allow traffic over HTTP, HTTPS, and SSH ports. While testing, you specifically try to reach the server over multiple ports and protocols; however, you do not see any denied connections in the firewall logs. You want to resolve the issue.What should you do?
A. Enable logging on the default Deny Any Firewall Rule
B. Enable logging on the VM Instances that receive traffic
C. Create a logging sink forwarding all firewall logs with no filters
D. Create an explicit Deny Any rule and enable logging on the new rule
View answer
Correct Answer: B
Question #43
You are designing a shared VPC architecture. Your network and security team has strict controls over which routes are exposed between departments. Your Production and Staging departments can communicate with each other, but only via specific networks. You want to follow Google-recommended practices.How should you design this topology?
A. Grant the compute
B. Grant the iam
C. Grant the read-only privilege to the service account for the Cloud Storage bucket
D. Grant the cloud-platform privilege to the service account for the Cloud Storage bucket
View answer
Correct Answer: D
Question #44
You have enabled HTTP(S) load balancing for your application, and your application developers have reported that HTTP(S) requests are not being distributed correctly to your Compute Engine Virtual Machine instances. You want to find data about how the request are being distributed.Which two methods can accomplish this? (Choose two.)
A. On the Load Balancer details page of the GCP Console, click on the Monitoring tab, select your backend service, and look at the graphs
B. In Stackdriver Error Reporting, look for any unacknowledged errors for the Cloud Load Balancers service
C. In Stackdriver Monitoring, select Resources > Metrics Explorer and search for https/request_bytes_count metric
D. In Stackdriver Monitoring, select Resources > Google Cloud Load Balancers and review the Key Metrics graphs in the dashboard
E. In Stackdriver Monitoring, create a new dashboard and track the https/backend_request_count metric for the load balancer
View answer
Correct Answer: AD

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number: