exam questions

Exam Professional Cloud Network Engineer All Questions

View all questions & answers for the Professional Cloud Network Engineer exam

Exam Professional Cloud Network Engineer topic 1 question 34 discussion

Actual exam question from Google's Professional Cloud Network Engineer
Question #: 34
Topic #: 1
[All Professional Cloud Network Engineer Questions]

Your company has recently expanded their EMEA-based operations into APAC. Globally distributed users report that their SMTP and IMAP services are slow.
Your company requires end-to-end encryption, but you do not have access to the SSL certificates.
Which Google Cloud load balancer should you use?

  • A. SSL proxy load balancer
  • B. Network load balancer
  • C. HTTPS load balancer
  • D. TCP proxy load balancer
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
densnoigaskogen
Highly Voted 3 years, 5 months ago
D should be the answer. "Globally distributed users report that their SMTP and IMAP services are slow" --> means it's needed to be global, traffic type is TCP. "end-to-end encryption" +"you do not have access to the SSL certificates" ---> means that you can not use client certificate to configure on LB to do SSL offload. As per the reference below, only TCP proxy Load Balancer. https://cloud.google.com/load-balancing/docs/choosing-load-balancer
upvoted 32 times
AzureDP900
1 year, 10 months ago
Agreed
upvoted 2 times
...
...
BobBui
Highly Voted 3 years, 7 months ago
I go with D, https://cloud.google.com/load-balancing/docs/choosing-load-balancer SSL offload yes >> SSL proxy SSL offload no >> TCP proxy
upvoted 10 times
...
Orzechowski
Most Recent 1 month, 4 weeks ago
Selected Answer: B
No access to SSL then you cannot do SSL offloading, you should do passthrough and let the backend deal with the SSL part
upvoted 1 times
Orzechowski
1 month, 4 weeks ago
actually correcting myself answer is D TCP proxy load balancer, you have an option to use SSL offload but you don't have to. so you do not need access to the SSL certificates and still make use of the Global availability
upvoted 2 times
...
...
saraali
2 months, 3 weeks ago
Selected Answer: D
The correct answer is D. The TCP proxy load balancer is ideal for applications like SMTP and IMAP that require end-to-end encryption but where SSL certificates are not accessible. It operates at the transport layer (Layer 4) and provides secure, encrypted traffic forwarding for non-HTTP(S) protocols such as IMAP and SMTP. It ensures that your traffic remains encrypted while reducing latency for globally distributed users. The other load balancers either require access to SSL certificates (SSL Proxy and HTTPS load balancers) or are not suitable for Layer 4 protocols (Network Load Balancer).
upvoted 1 times
...
RKS_2021
3 months, 2 weeks ago
Selected Answer: A
TCP Proxy load balancer does not provide the end to end encryption by itself.
upvoted 1 times
...
irmingard_examtopics
7 months, 1 week ago
Selected Answer: A
Not HTTP => Network LB category Passthrough is not global => Global External Proxy Network LB Since creating a Google-managed certificate should still be possible, question A is correct (Global External Proxy Network LB with SSL).
upvoted 1 times
...
desertlotus1211
8 months, 2 weeks ago
I've changed my answer to B here's why: Both SSL Proxy and TCP Proxy Load Balancers are designed for situations where you can terminate SSL sessions at the load balancer level, allowing for SSL offloading. However, they are not suitable for scenarios requiring end-to-end encryption without SSL termination at the load balancer, especially when SSL certificates are not available for such termination. Since you have no access to SSL certificate you cannot offload it... Therefore it's the responsibility of the end devices. So you the best answer now is Answer B: Network Load Balancer
upvoted 3 times
...
xhilmi
10 months, 3 weeks ago
Selected Answer: D
Explanation: The TCP proxy load balancer operates at the transport layer (Layer 4) and is designed for TCP-based protocols like SMTP and IMAP. Unlike the HTTPS load balancer, the TCP proxy load balancer does not terminate SSL, making it suitable for scenarios where SSL certificates are not accessible or not required. It allows you to distribute TCP traffic without handling SSL encryption or decryption, making it a good choice when end-to-end encryption is not a strict requirement.
upvoted 2 times
...
Thornadoo
1 year, 2 months ago
Selected Answer: D
This is D. I know this isn't super clear in the docs. But the best way to identify is as below: 1) If you go to SSL Proxy (https://cloud.google.com/load-balancing/docs/ssl/setting-up-ssl), you have to choose a certificate (There is no option to do away without it) 2) If you select TCP Proxy (https://cloud.google.com/load-balancing/docs/tcp/setting-up-tcp), there is no need to choose certificate
upvoted 4 times
...
Komal697
1 year, 7 months ago
Selected Answer: A
Since end-to-end encryption is required, the SSL Proxy Load Balancer is the appropriate choice as it allows the SSL/TLS traffic to pass through to the backends unchanged, preserving end-to-end encryption. Network Load Balancer and TCP Proxy Load Balancer do not provide end-to-end encryption for the application protocol. HTTPS Load Balancer is not appropriate because you do not have access to the SSL certificates.Therefore, the correct answer is A. SSL proxy load balancer.
upvoted 1 times
...
afeedik
1 year, 7 months ago
Selected Answer: A
A is the correct answer. https://cloud.google.com/load-balancing/docs/ssl#ssl_certificates
upvoted 1 times
...
pk349
1 year, 9 months ago
D: It specifically states they don't”have access to the SSL certs" not that they don't have them at all. This means they are unable to configure the client SSL certs on the LB itself and SSL offload is not required. Answer points to D for TCP Proxy.
upvoted 2 times
desertlotus1211
1 year, 2 months ago
I tend to agree with answer D. They have the certs, but have no one access them...
upvoted 1 times
...
...
gdtoro
1 year, 10 months ago
TCP Load Balancer doesn't require a certificate and can route encrypted traffic.
upvoted 1 times
...
flyhighman
1 year, 10 months ago
Selected Answer: D
D is right.
upvoted 3 times
...
TD24
1 year, 10 months ago
I would go with D
upvoted 3 times
...
pfilourenco
1 year, 11 months ago
Selected Answer: D
Answer is : D
upvoted 4 times
...
ccieman2016
1 year, 11 months ago
Selected Answer: D
D is sure for me.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago