exam questions

Exam Professional Cloud Network Engineer All Questions

View all questions & answers for the Professional Cloud Network Engineer exam

Exam Professional Cloud Network Engineer topic 1 question 98 discussion

Actual exam question from Google's Professional Cloud Network Engineer
Question #: 98
Topic #: 1
[All Professional Cloud Network Engineer Questions]

Your company’s on-premises network is connected to a VPC using a Cloud VPN tunnel. You have a static route of 0.0.0.0/0 with the VPN tunnel as its next hop defined in the VPC. All internet bound traffic currently passes through the on-premises network. You configured Cloud NAT to translate the primary IP addresses of Compute Engine instances in one region. Traffic from those instances will now reach the internet directly from their VPC and not from the on-premises network. Traffic from the virtual machines (VMs) is not translating addresses as expected. What should you do?

  • A. Lower the TCP Established Connection Idle Timeout for the NAT gateway.
  • B. Add firewall rules that allow ingress and egress of the external NAT IP address, have a target tag that is on the Compute Engine instances, and have a priority value higher than the priority value of the default route to the VPN gateway.
  • C. Add a default static route to the VPC with the default internet gateway as the next hop, the network tag associated with the Compute Engine instances, and a higher priority than the priority of the default route to the VPN tunnel.
  • D. Increase the default min-ports-per-vm setting for the Cloud NAT gateway.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ccieman2016
Highly Voted 11 months ago
Selected Answer: C
A and D no make sense for me, because Cloud NAT is manage service by GCP, adjusts theses especific parameter, non sense. B is wrong, you cannot adjust firewall rules. for me, letter C is correct.
upvoted 9 times
AzureDP900
10 months, 3 weeks ago
yes, I agree C is right. C. Add a default static route to the VPC with the default internet gateway as the next hop, the network tag associated with the Compute Engine instances, and a higher priority than the priority of the default route to the VPN tunnel. Most Voted
upvoted 2 times
...
...
Komal697
Most Recent 7 months ago
Selected Answer: C
Option C is correct because adding a default static route to the VPC with the default internet gateway as the next hop, the network tag associated with the Compute Engine instances, and a higher priority than the priority of the default route to the VPN tunnel, will ensure that the traffic from the Compute Engine instances that needs to reach the internet will go through the Cloud NAT gateway, which is the default internet gateway in this case.
upvoted 2 times
...
Ben756
7 months, 3 weeks ago
Selected Answer: C
According to a Google Cloud documentation, Cloud NAT allows VM instances without external IP addresses and private GKE clusters to send outbound packets to the internet and receive any corresponding established inbound response packets. However, Cloud NAT does not work if a VM has a route that directs its outbound traffic through a VPN tunnel. Therefore, the correct answer is C. Add a default static route to the VPC with the default internet gateway as the next hop, the network tag associated with the Compute Engine instances, and a higher priority than the priority of the default route to the VPN tunnel. This option allows you to override the default route that directs all traffic through the VPN tunnel for only those instances that have a specific network tag. This way, those instances can use Cloud NAT for their outbound traffic.
upvoted 2 times
...
SZON
8 months ago
C should be the correct one
upvoted 1 times
...
GreenAppl_e
11 months ago
A. https://cloud.google.com/nat/docs/overview#specs-timeouts
upvoted 1 times
ccieman2016
11 months ago
Times there's, but we cann't change anything. C is correct here.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago