exam questions

Exam Professional Cloud Network Engineer All Questions

View all questions & answers for the Professional Cloud Network Engineer exam

Exam Professional Cloud Network Engineer topic 1 question 35 discussion

Actual exam question from Google's Professional Cloud Network Engineer
Question #: 35
Topic #: 1
[All Professional Cloud Network Engineer Questions]

Your company is working with a partner to provide a solution for a customer. Both your company and the partner organization are using GCP. There are applications in the partner's network that need access to some resources in your company's VPC. There is no CIDR overlap between the VPCs.
Which two solutions can you implement to achieve the desired results without compromising the security? (Choose two.)

  • A. VPC peering
  • B. Shared VPC
  • C. Cloud VPN
  • D. Dedicated Interconnect
  • E. Cloud NAT
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ESP_SAP
Highly Voted 4 years ago
Correct Answer are (A) & (C): The solution is incorrect. GCP recommends creating VPC peering for establishing communication between two organizations in GCP.
upvoted 24 times
AzureDP900
1 year, 11 months ago
Agreed
upvoted 2 times
...
...
small1_small2
Highly Voted 2 years, 2 months ago
Selected Answer: AC
VPC peering offers peering between VPC which will suffice the requirement =A C is 100% correct
upvoted 5 times
...
saraali
Most Recent 2 months, 2 weeks ago
Selected Answer: AC
Reason:The correct answers are A& C. A. VPC peering: This solution allows two VPCs, in this case, your company's and the partner's VPCs, to communicate securely without needing a VPN or a shared network. Since there is no CIDR overlap between the VPCs, VPC peering is a great choice for private communication between the VPCs. C. Cloud VPN: If you want to securely connect your company's VPC to the partner's network (or their VPC), Cloud VPN is a good solution. It provides an encrypted connection over the public internet. It doesn’t require CIDR overlap, making it suitable for your scenario.
upvoted 1 times
...
Kyle1776
12 months ago
For everyone saying C Cloud VPN, I ask you to lab it up real quick. Please try and create a VPN connection between 2 VPCs in separate organizations. You will not be able to because when you are creating a VPN connection and select GCP as the VPN Peer gateway, the only options available to connect you are your VPC's. Not your partners in a different organization.
upvoted 1 times
BenMS
10 months, 1 week ago
Did you test this using the Console? Because VPN should be the most flexible solution, but it's possible the Console is making some assumptions in your case. Perhaps try the CLI? A VPN tunnel needs only an IP address for the peer gateway to initiate a connection - because the peer could be any network appliance.
upvoted 1 times
...
...
Kyle1776
1 year ago
I see everyone on here saying that you can use cloud VPN but the VPN gateways also have to be within the same organization in order to connect. Facing the same issue as the shared VPC. In my lab when I go to create a VPN tunnel between 2 different VPC's in different organizations this message pops up "Make sure you created a VPN gateway in the Google Cloud project that you want to connect." You then have to select the project you are connecting to. This implies that if the VPC/project are not in your org then you cant create a VPN between the two.
upvoted 1 times
...
Thornadoo
1 year, 3 months ago
Selected Answer: AC
This is really not a difficult question folks - here's my explanation A. VPC peering (Correct - Now I know this opens up the subnet, and there should be an additional step of configuring firewall rules IMO - but peering can be done between two different organizations) B. Shared VPC (Incorrect - We are talking about company and partner - meaning different organization. Shared VPC is applicable only for projects in the same org - https://cloud.google.com/vpc/docs/shared-vpc) C. Cloud VPN (Correct - With Cloud VPN you get additional layer of security of encryption) D. Dedicated Interconnect (Incorrect - Both use GCP. If it was different cloud, then cross connect or on-prem then interconnect) E. Cloud NAT (Incorrect - Not needed. With peering itself all subnets can communicate using internal IPv4 addresses - https://cloud.google.com/vpc/docs/vpc-peering)
upvoted 4 times
...
due
1 year, 5 months ago
please someone explain. Why not B. Shared VPC
upvoted 1 times
gcpengineer
1 year, 2 months ago
not in same org
upvoted 1 times
Kyle1776
1 year ago
You have the same issue for VPN though
upvoted 1 times
...
...
...
Komal697
1 year, 7 months ago
Selected Answer: AD
The two solutions that can be implemented to achieve the desired results without compromising the security are VPC peering and Dedicated Interconnect. A. VPC peering allows connecting two VPC networks through a private network connection. This solution provides private connectivity between the two VPCs without the need for public IPs or internet connectivity. D. Dedicated Interconnect allows for establishing a dedicated network connection between the two networks over a private, high-throughput, low-latency connection. This solution provides a dedicated and private connection between the two networks.
upvoted 1 times
gcpengineer
1 year, 2 months ago
interconnect is between on prem n gcp. not between 2 gcp env
upvoted 2 times
...
...
pk349
1 year, 9 months ago
Correct Answer are (A) & (C): The solution is incorrect. GCP recommends creating VPC peering for establishing communication between two organizations in GCP. Dedicated interconnect is used to connect on prem to GCP, not GCP to GCP. D is not correct. VPC peering allows this to occur between GCP VPCs. Dedicated interconnect enables hybrid cloud - meaning if only on-prem network needs connectivity with Google Cloud. Question clearly mention only VPC between org. Hence D is wrong!
upvoted 1 times
...
AzureDP900
1 year, 11 months ago
A,C is perfect
upvoted 1 times
...
hogtrough
1 year, 11 months ago
Selected Answer: AC
Dedicated interconnect is used to connect on prem to GCP, not GCP to GCP. D is not correct. VPC peering allows this to occur between GCP VPCs.
upvoted 4 times
...
Jasonwcc
2 years, 2 months ago
Boys oh boys, Dedicated interconnect enables hybrid cloud - meaning if only on-prem network needs connectivity with Google Cloud. Question clearly mention only VPC between org. hence D is wrong!
upvoted 2 times
...
GCP72
2 years, 2 months ago
Selected Answer: AC
The correct answer is A & C
upvoted 4 times
...
ssarabj
2 years, 6 months ago
C is 100% accurate D is wrong as interconnect only comes in picture when we need to enable connectivity between on prem and gcp A is partially fits in picture as give access to all resource but requirement says need access on few resources.
upvoted 2 times
...
marcosilva79
2 years, 8 months ago
for sure te correct answer is (A) and (C).
upvoted 1 times
...
marcosilva79
2 years, 9 months ago
A and C are correct .
upvoted 1 times
...
yas_cloud
2 years, 9 months ago
There is no question of going with Dedicated Interconnect when you have both networks on GCP. Easily we can implement the solution using Peering and VPN. Hence A and C.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago