Free Professional-Cloud-Network-Engineer Exam Braindumps

Pass your Google Cloud Certified - Professional Cloud Network Engineer exam with these free Questions and Answers

Page 8 of 31
QUESTION 31

Your company has defined a resource hierarchy that includes a parent folder with subfolders for each department. Each department defines their respective project and VPC in the assigned folder and has the appropriate permissions to create Google Cloud firewall rules. The VPCs should not allow traffic to flow between them. You need to block all traffic from any source, including other VPCs, and delegate only the intra-VPC firewall rules to the respective departments. What should you do?

  1. A. Create a VPC firewall rule in each VPC to block traffic from any source, with priority 0.
  2. B. Create a VPC firewall rule in each VPC to block traffic from any source, with priority 1000.
  3. C. Create two hierarchical firewall policies per department's folder with two rules in each: a high-priority rule that matches traffic from the private CIDRs assigned to the respective VPC and sets the action to allow, and another lower-priority rule that blocks traffic from any other source.
  4. D. Create two hierarchical firewall policies per department's folder with two rules in each: a high-priority rule that matches traffic from the private CIDRs assigned to the respective VPC and sets the action to goto_next, and another lower-priority rule that blocks traffic from any other source.

Correct Answer: B

QUESTION 32

You want to set up two Cloud Routers so that one has an active Border Gateway Protocol (BGP) session, and the other one acts as a standby.
Which BGP attribute should you use on your on-premises router?

  1. A. AS-Path
  2. B. Community
  3. C. Local Preference
  4. D. Multi-exit Discriminator

Correct Answer: D

QUESTION 33

You work for a multinational enterprise that is moving to GCP. These are the cloud requirements:
• An on-premises data center located in the United States in Oregon and New York with Dedicated Interconnects connected to Cloud regions us-west1 (primary HQ) and us-east4 (backup)
• Multiple regional offices in Europe and APAC
• Regional data processing is required in europe-west1 and australia-southeast1
• Centralized Network Administration Team
Your security and compliance team requires a virtual inline security appliance to perform L7 inspection for URL filtering. You want to deploy the appliance in us-west1.
What should you do?

  1. A. • Create 2 VPCs in a Shared VPC Host Project.• Configure a 2-NIC instance in zone us-west1-a in the Host Project.• Attach NIC0 in VPC #1 us-west1 subnet of the Host Project.• Attach NIC1 in VPC #2 us-west1 subnet of the Host Project.• Deploy the instance.• Configure the necessary routes and firewall rules to pass traffic through the instance.
  2. B. • Create 2 VPCs in a Shared VPC Host Project.• Configure a 2-NIC instance in zone us-west1-a in the Service Project.• Attach NIC0 in VPC #1 us-west1 subnet of the Host Project.• Attach NIC1 in VPC #2 us-west1 subnet of the Host Project.• Deploy the instance.• Configure the necessary routes and firewall rules to pass traffic through the instance.
  3. C. • Create 1 VPC in a Shared VPC Host Project.• Configure a 2-NIC instance in zone us-west1-a in the Host Project.• Attach NIC0 in us-west1 subnet of the Host Project.• Attach NIC1 in us-west1 subnet of the Host Project• Deploy the instance.• Configure the necessary routes and firewall rules to pass traffic through the instance.
  4. D. • Create 1 VPC in a Shared VPC Service Project.• Configure a 2-NIC instance in zone us-west1-a in the Service Project.• Attach NIC0 in us-west1 subnet of the Service Project.• Attach NIC1 in us-west1 subnet of the Service Project• Deploy the instance.• Configure the necessary routes and firewall rules to pass traffic through the instance.

Correct Answer: B
https://cloud.google.com/vpc/docs/shared-vpc

QUESTION 34

You suspect that one of the virtual machines (VMs) in your default Virtual Private Cloud (VPC) is under a denial-of-service attack. You need to analyze the incoming traffic for the VM to understand where the traffic is coming from. What should you do?

  1. A. Enable Data Access audit logs of the VP
  2. B. Analyze the logs and get the source IP addresses from the subnetworks.get field.
  3. C. Enable VPC Flow Logs for the subne
  4. D. Analyze the logs and get the source IP addresses from the connection field.
  5. E. Enable VPC Flow Logs for the VP
  6. F. Analyze the logs and get the source IP addresses from the src_location field.
  7. G. Enable Data Access audit logs of the subne
  8. H. Analyze the logs and get the source IP addresses from the networks.get field.

Correct Answer: B

QUESTION 35

You have configured Cloud CDN using HTTP(S) load balancing as the origin for cacheable content. Compression is configured on the web servers, but responses served by Cloud CDN are not compressed.
What is the most likely cause of the problem?

  1. A. You have not configured compression in Cloud CDN.
  2. B. You have configured the web servers and Cloud CDN with different compression types.
  3. C. The web servers behind the load balancer are configured with different compression types.
  4. D. You have to configure the web servers to compress responses even if the request has a Via header.

Correct Answer: D
If responses served by Cloud CDN are not compressed but should be, check that the web server software running on your instances is configured to compress responses. By default, some web server software will automatically disable compression for requests that include a Via header. The presence of a Via header indicates the request was forwarded by a proxy. HTTP proxies such as HTTP(S) load balancing add a Via header to each request as required by the HTTP specification. To enable compression, you may have to override your web server's default configuration to tell it to compress responses even if the request had a Via header.

Page 8 of 31

Post your Comments and Discuss Google Professional-Cloud-Network-Engineer exam with other Community members: