Google Cloud · Free Practice Questions · Last reviewed May 2026
42real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
16% of exam · 6 sample questions below
A large enterprise is migrating to Google Cloud and needs to establish connectivity between on-premises and VPCs in two different regions (us-east1 and europe-west1). They have a single Partner Interconnect connection at a co-location facility in New York. They want to use the same interconnect for both regions. Which configuration should they use?
Create two VLAN attachments, one for each region, over the same interconnect
A single Partner Interconnect supports multiple VLAN attachments, each terminating in a different region. Creating one attachment per region over the same interconnect extends on-premises reachability to both us-east1 and europe-west1 without provisioning separate connections.
Create one VLAN attachment and attach it to both VPCs
Use HA VPN over the interconnect to connect both regions
Create two Cloud VPN tunnels from on-prem to each VPC
A company is using Cloud DNS for private zone resolution within their VPC. They have a private zone for 'example.internal' and have attached it to the VPC. When they create a new Compute Engine VM and try to resolve 'myapp.example.internal', it fails. What is the most likely cause?
The private zone is not attached to the VPC
The VM's /etc/resolv.conf does not point to Cloud DNS
Firewall rule blocking DNS traffic (UDP 53) to the metadata server
The record 'myapp.example.internal' does not exist in the zone
The zone is attached and Cloud DNS resolves existing records, so resolution failure for a specific name indicates the record itself is absent. Creating the missing A record for myapp.example.internal in the private zone resolves the issue.
You have a Cloud Router with the configuration shown. The on-premises network (ASN 65002) is not receiving any routes from Google Cloud. What is the most likely cause?
The BGP keepalive interval is set too low
The BGP session is not established
The router is in custom advertise mode but does not advertise the VPC subnets
In custom advertise mode, Cloud Router advertises only the routes you explicitly list. If the VPC subnets are not added to the advertised route set, the on-premises ASN 65002 receives no prefixes from Google Cloud, which exactly matches the reported symptom.
The on-premises subnet 10.0.1.0/24 is not advertised
Which TWO considerations are important when designing a VPC peering strategy between multiple projects in Google Cloud?
Peering is transitive by default
Subnet IP ranges in peered VPCs must not overlap
VPC peering requires non-overlapping subnet IP ranges across peered networks; overlapping CIDRs cause route conflicts and the peering cannot be established. This constraint must be planned before peering multiple projects, since ranges cannot be changed afterwards without recreating subnets.
Firewall rules in one VPC automatically apply to peered VPCs
VPC peering can only be used within the same project
Custom routes can be exchanged between peered VPCs if configured
Custom routes can be exported and imported across peered VPCs, but only when both networks explicitly enable the setting; by default, peering exchanges only subnet routes. This satisfies the stem's multi-project design constraint, since shared custom routes determine reachability for on-premises or appliance traffic between projects.
Which THREE actions should you take to secure a VPC that hosts public-facing web applications?
Assign public IP addresses to all VMs for direct internet access
Use Cloud NAT to allow outbound internet access without public IPs
Cloud NAT lets instances without external IP addresses initiate outbound connections, so backend VMs behind the load balancer are not directly reachable from the internet. This removes public IP exposure while preserving patching and update egress.
Enable VPC Flow Logs to block malicious traffic
Enable Cloud Armor to protect against DDoS and application attacks
Cloud Armor attaches security policies to the external load balancer, filtering malicious traffic at Google's edge before it reaches backends. It provides the layer 7 rules and DDoS protection that satisfy the requirement to defend public-facing web applications.
Use Private Google Access for VMs that need to access Google APIs
Private Google Access lets VMs without external IP addresses reach Google APIs and services over internal addresses, removing the need to expose them publicly. This satisfies the stem's constraint of securing a public-facing VPC by keeping backend VMs private while still allowing required API calls.
A company is deploying a global application on Google Cloud using Cloud Load Balancing. They want to serve traffic from multiple regions and require the lowest possible latency for users worldwide. The application serves HTTP traffic and uses a static IP address. Which load balancing solution should they use?
Network Load Balancer
Internal HTTP(S) Load Balancer
SSL Proxy Load Balancer
External HTTP(S) Load Balancer with Premium Tier
External HTTP(S) Load Balancer with Premium Tier uses Google's global network and anycast IP to direct users to the nearest backend, minimizing latency.
Want more Configuring Network Services practice?
Practice this domain14% of exam · 6 sample questions below
A network engineer needs to verify that traffic from a specific Compute Engine instance can reach a Cloud SQL database in a different VPC. Which Google Cloud tool should be used to test this reachability?
Connectivity Tests
Connectivity Tests performs a live trace between a Compute Engine instance and a Cloud SQL endpoint across VPCs, evaluating firewall rules, routes and peering to confirm reachability. It satisfies the cross-VPC verification constraint directly, unlike flow logs or firewall rule analysis, which show configuration rather than end-to-end path viability.
Cloud Monitoring
Network Topology
VPC Flow Logs
A company wants to analyze VPC Flow Logs to understand which external IPs are generating the most outbound traffic. What is the most scalable way to store and query these logs?
BigQuery
BigQuery ingests VPC Flow Logs at scale and runs fast SQL aggregations over billions of rows, letting you group by external IP and sum outbound bytes. This satisfies the scalability constraint far better than querying raw log files.
Cloud Storage and analyze with gsutil
Cloud Logging with Logs Explorer
Cloud Monitoring Metrics
Which Network Intelligence Center tool provides a visual representation of your VPC network, including instances, subnets, firewall rules, and routes?
Connectivity Tests
Firewall Insights
Network Topology
Network Topology in Network Intelligence Center renders a visual graph of the VPC, showing instances, subnets, firewall rules, and routes as connected entities. This directly satisfies the stem's requirement for a visual representation of those components, unlike metrics or connectivity test tools.
Performance Dashboard
A security team wants to capture all traffic from a Compute Engine instance for intrusion detection. Which service should be used to copy traffic to a third-party IDS appliance running on another instance?
Packet Mirroring
Packet Mirroring copies ingress and egress traffic from a Compute Engine instance to a collector, letting you forward packets to a third-party IDS appliance on another instance. It satisfies the requirement to capture all traffic without installing agents on the monitored VM.
Firewall Rules logging
VPC Flow Logs
Cloud NAT logging
A company is using Cloud NAT for outbound traffic. They want to log when a connection fails due to resource exhaustion. Which logging feature should be enabled?
Cloud NAT logging with filter for errors
Cloud NAT logging captures connection and allocation failures.
Firewall Rules logging
VPC Flow Logs on the subnet
Cloud Armor request logs
An organization needs to reduce egress costs for a global application serving users worldwide. The application serves static content from Compute Engine instances. Which action is most cost-effective?
Move all instances to a single region to reduce cross-region traffic
Use Cloud CDN to cache content at edge locations
Cloud CDN caches static content at Google edge locations, so user requests terminate near the user rather than traversing to Compute Engine instances. This reduces bytes served from origin regions, directly lowering egress charges for a globally distributed audience.
Upgrade to premium tier networking
Enable Private Google Access
Want more Managing, Monitoring, and Optimising Network Operations practice?
Practice this domain16% of exam · 6 sample questions below
A company is deploying a Dedicated Interconnect with a 10 Gbps circuit to Google Cloud. They need to ensure high availability. Which configuration is required by Google Cloud to meet the high availability SLA?
Combine Dedicated Interconnect with a Cloud VPN tunnel for failover
Use Partner Interconnect instead of Dedicated Interconnect
Provision two VLAN attachments on two separate Cloud Routers in different zones
Two VLAN attachments terminating on separate Cloud Routers in distinct zones satisfy Google's 99.99% Dedicated Interconnect SLA, which requires redundant connectivity across two metro availability zones. A single attachment or shared router leaves a zonal failure domain, so this topology removes that single point of failure.
Provision a single VLAN attachment on one Cloud Router
A multinational corporation is connecting five on-premises data centers to Google Cloud using Cloud Interconnect. Each data center has a dedicated 10 Gbps connection. They want to ensure that if one Interconnect fails, traffic is automatically redistributed across the remaining connections without manual intervention. Which solution meets this requirement?
Configure multiple VLAN attachments on a single Cloud Router and rely on link aggregation
Deploy Cloud VPN tunnels as backup and configure static routes with lower priority
Configure VPC Network Peering between all data centers and Google Cloud
Use a Cloud Router with BGP and establish multiple BGP sessions over each Interconnect
Multiple BGP sessions per Interconnect let Cloud Router detect individual link failures and withdraw only the affected routes, so BGP reconverges and redistributes traffic across the surviving 10 Gbps attachments automatically. This satisfies the no-manual-intervention failover constraint, though redundancy across separate Interconnects is still required for full resilience.
A company wants to connect their VPC to an on-premises network using Cloud VPN. They need to ensure that traffic from Google Cloud to on-premises uses a specific route only when the primary path is available, and otherwise fails over to a backup path. Which configuration should they use?
Configure Cloud NAT to route traffic through the backup path
Configure BGP on Cloud Router and advertise custom routes with appropriate metrics
BGP with Cloud Router lets you advertise custom routes carrying MED or priority attributes, so the primary path is preferred and the backup takes over only when the primary becomes unavailable, satisfying the failover requirement.
Use static routes with a higher priority for the primary path
Create firewall rules to allow failover traffic
A company has a Hybrid Connectivity setup using Cloud VPN with BGP. They want to migrate to Dedicated Interconnect for better performance. During the migration, they need to avoid downtime. Which THREE steps should they take?
Set a lower local preference on the Interconnect BGP session
Remove the VPN tunnels immediately after Interconnect is up
Provision the Dedicated Interconnect and VLAN attachments
Provisioning the Dedicated Interconnect and its VLAN attachments establishes the new physical and logical path before any traffic shifts. This satisfies the no-downtime constraint by building the parallel link while Cloud VPN with BGP continues carrying production traffic undisturbed.
Configure BGP on the Interconnect with a higher local preference than the VPN
Setting a higher local preference on the Interconnect BGP session makes Cloud Router prefer Interconnect-learned routes over VPN-learned ones, shifting egress traffic without tearing down the VPN. This satisfies the no-downtime constraint by making the cutover gradual and reversible.
Gradually withdraw VPN routes after verifying Interconnect traffic
Withdrawing VPN routes only after confirming Interconnect is carrying traffic removes the redundant path safely. Verifying first satisfies the no-downtime constraint, since the VPN remains a fallback until the Interconnect proves stable and fully operational.
Refer to the exhibit. The Cloud Router shows one BGP peer as ESTABLISHED and one as IDLE. The best routes show two routes to the same destination with different priorities. What is the most likely reason the IDLE peer is not establishing?
The on-premises router is not sending routes for the IDLE peer
The IDLE peer has a higher priority route, so it is not needed
BGP configuration mismatch between Cloud Router and on-premises router for the IDLE peer
An IDLE BGP peer never reaches ESTABLISHED, indicating the session cannot negotiate. Mismatched BGP parameters between the Cloud Router and the on-premises router, such as ASN or authentication settings, prevent session establishment for that peer.
The IDLE peer is not configured on the Cloud Router
An organization is using Cloud VPN with dynamic routing (BGP) to connect their on-premises network to Google Cloud. They notice that traffic from Google Cloud to on-premises is not using the VPN tunnel but instead going through the internet. They have verified that the VPN tunnel is up and BGP sessions are established. Which configuration issue is most likely causing this behavior?
The Cloud Router BGP IP address is misconfigured
The pre-shared key for the VPN tunnel is mismatched
The on-premises BGP ASN is incorrect
The on-premises router is not advertising the on-premises CIDR via BGP
Cloud Router only installs on-premises routes learned via BGP into the VPC. If the on-premises router does not advertise its CIDR, no route exists for that prefix, so return traffic exits via the default internet path despite the tunnel and BGP session being up.
Want more Implementing Hybrid Interconnectivity practice?
Practice this domain21% of exam · 6 sample questions below
Your company is deploying a multi-tier web application on Google Kubernetes Engine (GKE) with a regional cluster. You need to design network policies to allow traffic only from the frontend pods to the backend pods on port 8080. Which of the following is the most secure and recommended approach?
Define a Kubernetes NetworkPolicy that allows ingress to backend pods from frontend pods on port 8080.
A Kubernetes NetworkPolicy selects backend pods and permits ingress only from pods labelled as frontend on TCP 8080, enforcing least-privilege pod-level segmentation. This satisfies the requirement to restrict backend traffic to frontend sources on that specific port, rather than relying on broader IP-based rules.
Configure Private Service Connect to restrict access to backend pods.
Create VPC firewall rules to allow ingress from frontend pods to backend pods on port 8080.
Use Cloud Armor security policies to restrict traffic to backend pods.
A network engineer needs to design a VPC network for a global application that will have Compute Engine instances in multiple regions. The instances need to communicate with each other using internal IP addresses. What is the simplest way to enable this communication?
Use Dedicated Interconnect to connect regions.
Use Cloud VPN to connect the instances.
Create a single VPC network with subnets in each region.
A single VPC network is global in GCP, so subnets in each region share one routing domain. Instances in different regions reach each other over internal IP addresses without VPNs, peering or extra gateways, satisfying the multi-region internal communication requirement with the least configuration.
Create separate VPC networks per region and peer them.
Which TWO of the following are valid methods to reduce latency between users in Europe and a GCP-hosted application?
Establish a Cloud VPN tunnel to the user's ISP.
Use Cloud CDN to cache content at edge locations.
Cloud CDN caches responses at Google edge points of presence, so European users are served from nearby locations rather than crossing to the origin region. This cuts round-trip distance and backhaul, directly reducing the latency the scenario describes.
Use Premium Tier networking instead of Standard Tier.
Use Cloud NAT for outbound traffic.
Deploy Compute Engine instances in a European region.
Placing Compute Engine instances in a European region puts the workload physically near European users, shortening network round-trip distance. Serving requests locally rather than from a distant region is the direct mechanism that lowers the latency described.
A network engineer is troubleshooting connectivity from a Compute Engine instance in subnet-a to a Google Cloud Storage bucket. The instance has no external IP address. Based on the exhibit, what is the most likely cause of the connectivity issue?
The subnet purpose is PRIVATE, which blocks Google APIs.
Private Google Access is disabled on the subnet.
Private Google Access lets instances without external IP addresses reach Google APIs and services such as Cloud Storage using internal routing. With it disabled on subnet-a, the instance has no path to the bucket's API endpoint, causing the connectivity failure.
The subnet CIDR range is too small.
Flow logs are disabled, so traffic is not logged.
Based on the exhibit, what is the purpose of Cloud Router's BGP configuration?
To advertise the VPC's IP range to the on-premises network.
Cloud Router runs BGP to exchange routes dynamically between the VPC and on-premises network. Advertising the VPC subnet range lets on-premises routers learn the destination prefixes, enabling return traffic to reach Google Cloud workloads without static routes.
To load balance traffic across multiple VPN tunnels.
To receive a default route from the on-premises network.
To advertise a default route to the on-premises network.
A company has a VPC with subnets in us-east1 and europe-west1. They have a Compute Engine instance in us-east1 with an internal IP 10.0.1.2. They need to allow SSH (port 22) from a specific on-premises IP 203.0.113.5 via Cloud VPN. The Cloud VPN tunnel uses a Cloud Router with BGP. The on-premises network advertises the route for 203.0.113.5/32 to the Cloud Router. Which firewall rule must be created?
Ingress rule: source 203.0.113.5/32, destination 169.254.0.1/32, tcp:22
Ingress rule: source 10.0.1.2/32, destination 203.0.113.5/32, tcp:22
Ingress rule: source 0.0.0.0/0, destination 203.0.113.5/32, tcp:22
Ingress rule: source 203.0.113.5/32, destination 10.0.1.2/32, tcp:22
Ingress rules are evaluated against the packet's source address, so the on-premises host must be matched by its advertised 203.0.113.5/32 rather than the VPN gateway's address. The destination narrows to the instance's internal IP, and tcp:22 permits SSH.
Want more Designing, Planning, and Prototyping a GCP Network practice?
Practice this domain10% of exam · 6 sample questions below
An engineer needs to provide outbound internet access to a set of Compute Engine instances that have only internal IP addresses. The instances must use a static IP address for outbound traffic. Which solution should they implement?
Create a Cloud NAT gateway with static IP address and configure it on the VPC network.
Cloud NAT provides outbound internet access for instances with only internal IP addresses, satisfying the no-external-IP constraint. Reserving a static IP for the NAT gateway ensures all egress traffic presents that single fixed address, meeting the static outbound IP requirement. It operates at the VPC network level without per-instance configuration.
Assign a static external IP to each instance and configure a firewall rule to allow egress.
Configure Private Google Access on the subnet to route traffic to Google APIs.
Deploy a Compute Engine instance as a NAT instance with IP forwarding enabled.
A security team wants to enforce a policy that blocks all egress traffic to the internet from a specific set of VMs across multiple projects in an organization. The policy should be centrally managed and override VPC-level firewall rules. Which approach should they use?
Create VPC firewall rules with deny egress for the specific VMs in each VPC.
Deploy a hierarchical firewall policy at the organization level with a deny egress rule targeting the VMs.
A hierarchical firewall policy at the organisation level applies deny rules before VPC-level rules, so the egress block cannot be overridden by project firewalls. This satisfies the central management and override requirements, and targeting the specific VMs across projects enforces the restriction precisely where needed.
Use a network firewall policy attached to each VPC network.
Configure Cloud Armor security policies on the load balancer to block egress.
An organization needs to restrict access to Google Cloud APIs such that only traffic from a specific set of VMs inside a VPC can reach the APIs, and all other traffic (including from other VPCs) must be denied. The VMs do not have external IPs. Which combination of services should they use?
Private Service Connect and VPC Service Controls
Cloud NAT and VPC Service Controls
Private Google Access and VPC Service Controls
Private Google Access lets VMs without external IPs reach Google APIs internally, while VPC Service Controls enforce a perimeter that denies access from outside the designated VPCs. Together they satisfy the stem's requirement to permit only specified VMs and block all other traffic.
Cloud NAT and Private Google Access
A developer wants to allow HTTP (port 80) traffic from the internet to a set of Compute Engine instances that have a tag "web-server". Which firewall rule should they create?
Egress rule: source 0.0.0.0/0, target tag "web-server", tcp:80
Ingress rule: source 0.0.0.0/0, target tag "web-server", tcp:80
An ingress rule with source 0.0.0.0/0 permits internet traffic, the target tag "web-server" scopes it to the tagged Compute Engine instances, and protocol tcp:80 restricts it to HTTP on port 80, matching every constraint in the stem.
Egress rule: destination 0.0.0.0/0, target tag "web-server", tcp:80
Ingress rule: source 0.0.0.0/0, target service account "web-server", tcp:80
An organization uses a hierarchical firewall policy at the organization level with a deny-all egress rule (priority 100). They also have a VPC-level firewall rule allowing egress to a specific external IP (priority 1000). Will traffic to that external IP be allowed?
Yes, because VPC firewall rules override hierarchical policies for the same traffic.
Yes, because the VPC rule has a higher priority number and is more specific.
No, because hierarchical firewall policies take precedence over VPC firewall rules.
Hierarchical firewall policies are evaluated before VPC-level rules, so the organisation-level deny-all egress rule at priority 100 blocks the traffic regardless of the more permissive VPC rule at priority 1000. Priority values only order rules within the same policy level.
No, because both rules deny and allow cancel out, resulting in default deny.
An engineer wants to allow traffic from a specific service account to a Compute Engine instance. Which firewall rule option should they use for the source?
Source service accounts
Source service accounts lets the rule match traffic by the originating identity's service account rather than by IP range or network tag. This satisfies the requirement to permit only that specific service account's traffic to the instance.
Target service accounts
Source IP ranges
Source tags
Want more Implementing VPC Instances practice?
Practice this domain13% of exam · 6 sample questions below
A company is using Cloud NAT for internet access from private subnets. Security team notices that traffic from a specific VM is being blocked by external firewalls because the source IP is not the Cloud NAT IP. What is the most likely cause?
The VM is in a different zone than the Cloud NAT gateway
The VPC firewall rules are blocking outbound traffic from the VM to the Cloud NAT IP
Cloud Router is misconfigured and not advertising the Cloud NAT IP
The VM has a custom route that does not use the default route through Cloud NAT
Traffic must match the default route to be source NATed by Cloud NAT.
An organization wants to restrict access to a Cloud Storage bucket so that only VMs within a specific VPC network can download objects. They are using VPC Service Controls and Private Google Access. Which configuration is required?
Enable Cloud NAT and configure a firewall rule to allow egress to 0.0.0.0/0
Configure a Service Directory endpoint and attach an IAM policy to the bucket allowing access only from that endpoint
Create a firewall rule allowing egress to the storage.googleapis.com service IP range and enable VPC flow logs
Enable Private Google Access on the subnet and create a VPC Service Controls perimeter that includes the bucket project
Private Google Access enables internal IP access to Google APIs, and VPC Service Controls restricts access to the perimeter.
A network engineer is troubleshooting connectivity from an on-premises network to a GCE VM through a VPN tunnel. The tunnel is established, but traffic is not reaching the VM. What should the engineer check first?
Check VPC firewall rules to ensure ingress traffic from the on-premises subnet is allowed to the VM
With the tunnel established, the likely blocker is VPC firewall rules. GCE ingress rules are stateful and must explicitly permit traffic from the on-premises subnet to the VM's IP and port; checking these first isolates policy denial from routing or VPN faults.
Check the VM's OS firewall to see if it is blocking incoming traffic
Verify that the VPN tunnel is using the correct pre-shared key
Review Cloud Armor security policies that may be blocking the traffic
A company uses Cloud Armor to protect an HTTPS Load Balancer. They notice that legitimate traffic from a specific geographic region is being blocked. The security policy has a deny rule for that region. What is the correct way to allow traffic from that region while still protecting against attacks?
Remove the deny rule for that region and rely on other security measures
Add a new allow rule for that region with a lower priority number than the deny rule
Cloud Armor evaluates rules by priority, where the lowest number is evaluated first. Giving the allow rule a lower number than the region deny rule means matching traffic is permitted before the deny is reached, satisfying the requirement to admit that region while retaining attack protection.
Remove all rules and add a single allow rule for the legitimate region
Reorder the rules so that the deny rule is at the bottom of the list
A financial services company is migrating sensitive workloads to Google Cloud. They need to implement a defense-in-depth strategy to protect their VPC networks. Which TWO actions should they take to meet their security requirements? (Choose two.)
Enable Private Google Access on subnets that host instances without external IP addresses.
This allows instances to access Google APIs over the internal network, reducing exposure to the internet.
Configure firewall rules with stateful packet inspection disabled to maximize throughput.
Use VPC Service Controls to create a perimeter around the sensitive data stored in Cloud Storage and BigQuery.
VPC Service Controls help prevent data exfiltration by controlling access to Google Cloud services.
Use VPC Network Peering to isolate the sensitive workloads from other projects.
Create a Cloud NAT gateway to filter inbound traffic from the internet.
Drag and drop the steps to migrate an on-premises network to Google Cloud using a VPN and VPC peering into the correct order.
Create a new VPC in Google Cloud, then establish a VPN connection between on-premises and the new VPC, then configure BGP for dynamic routing, then set up VPC peering (if needed), and finally migrate workloads to the new VPC.
This is the correct order because a VPC must exist before you can terminate a VPN on it. After VPN connectivity, BGP enables dynamic routing. VPC peering connects to other VPCs, and workloads are migrated last.
Establish a VPN connection first, then configure BGP, then create a new VPC, then set up VPC peering, then migrate workloads.
Configure BGP first, then create a new VPC, then establish VPN, then set up VPC peering, then migrate workloads.
Create a new VPC, then set up VPC peering, then establish VPN, then configure BGP, then migrate workloads.
Want more Implementing network security practice?
Practice this domain10% of exam · 6 sample questions below
An organization is migrating to Google Cloud and requires connectivity between their on-premises network and VPC. They plan to use Cloud VPN with dynamic routing (BGP). Which VPC feature is required for this setup?
Cloud NAT
VPC peering
Cloud Router
Cloud Router provides the BGP speaker that Cloud VPN requires for dynamic route exchange, advertising on-premises prefixes into the VPC and learning Google Cloud routes in return. Without it, the HA VPN tunnels could only carry static routes, failing the stem's dynamic routing constraint.
VPC Flow Logs
A company has a VPC with a subnet in us-central1 and needs to allow HTTP traffic (port 80) from the internet to a VM instance. Which TWO configurations are required?
Configure Cloud NAT for the VPC.
Assign an external IP address to the VM.
An external IP address gives the VM a routable internet presence, which is required for inbound HTTP from external clients. Without it, the instance is reachable only internally, so the firewall rule alone cannot satisfy the internet-facing requirement.
Enable Private Google Access on the subnet.
Assign a static internal IP address to the VM.
Create a firewall rule to allow ingress on TCP port 80 from 0.0.0.0/0.
Firewall rules control ingress at the VPC level, so permitting TCP port 80 from 0.0.0.0/0 satisfies the internet-facing HTTP requirement. Without this rule, default ingress denies all external traffic, so the VM cannot receive port 80 requests regardless of its external IP.
A company is designing a VPC for a production environment that must meet the following requirements: support multiple projects, centralized network administration, and allow each project to have its own firewall rules. Which THREE components should be used?
Service projects
Service projects isolate workloads within a shared VPC host project, letting each project define its own firewall rules while network administration stays centralised. This satisfies the requirement for per-project firewall control without duplicating network management, since the host project retains ownership of subnets and the underlying VPC.
Host project
A host project centralises shared VPC network administration, letting a single network team own subnets, firewalls and routes while multiple service projects attach to it. This satisfies the centralised administration requirement, and firewall rules defined at the host level can be scoped per project, meeting the per-project firewall constraint.
Cloud VPN
VPC peering
Shared VPC
Shared VPC lets a host project's network host service projects' resources, so central administration sits with the host while each service project retains its own firewall rules. This directly satisfies the three stated constraints: multiple projects, centralised network administration, and per-project firewall control.
A company is migrating its on-premises infrastructure to Google Cloud. They need to connect their VPC to a third-party SaaS provider that only supports IPsec VPN. The company requires high availability and automatic failover. Which solution should they implement?
Deploy two Cloud VPN tunnels from two Cloud Routers with BGP sessions to the peer VPN device.
Two Cloud VPN tunnels terminating on two Cloud Routers, each running BGP sessions with the peer device, provide redundant IPsec paths. BGP withdraws routes when a tunnel fails, so traffic fails over automatically, satisfying the high-availability and automatic-failover requirements that a single tunnel cannot meet.
Use Dedicated Interconnect with VLAN attachments to the SaaS provider.
Deploy a Classic VPN tunnel with policy-based routing.
Deploy a single Cloud VPN tunnel and use static routing.
A company has deployed a global application on Compute Engine instances in multiple regions. Users are experiencing high latency connecting to the application. The network team wants to use Google Cloud's global network to improve performance. Which approach should they take?
Deploy a global HTTP(S) Load Balancer with backend services in each region.
A global external HTTP(S) load balancer uses Google's premium-tier global network to route each user to the nearest healthy backend region, terminating TCP close to the client. This directly addresses the high-latency constraint by avoiding long-haul public internet transit between regions.
Use Cloud DNS with geo-routing to direct users to regional load balancers.
Set up Cloud NAT with multiple static IP addresses for each region.
Assign a global anycast IP address to all instances and use BGP to advertise it.
A financial services company is deploying a multi-tier application in a custom VPC with three subnets: web (10.0.1.0/24), app (10.0.2.0/24), and db (10.0.3.0/24). They use a Cloud VPN with dynamic routing (BGP) to connect to their on-premises data center (10.1.0.0/16). The on-premises network administrator reports that traffic from the web tier (10.0.1.0/24) to on-premises is working, but traffic from the app tier (10.0.2.0/24) to on-premises is failing. The company uses an Identity-Aware Proxy (IAP) for SSH access. The following configurations are in place: - Cloud Router advertises all VPC subnets via BGP. - On-premises router advertises 10.1.0.0/16. - Firewall rules allow all traffic from 10.0.0.0/16 to 10.1.0.0/16. - The app tier instances have a network tag 'app-tier' and a service account 'app-sa@project.iam.gserviceaccount.com'. - There is a firewall rule with priority 1000 that denies egress from tags 'app-tier' to 10.1.0.0/16. What is the most likely cause of the failure?
The service account 'app-sa' does not have permissions to send traffic through the VPN.
IAP is blocking traffic from the app tier because it is not configured for that subnet.
A firewall egress rule with priority 1000 denies traffic from instances with tag 'app-tier' to 10.1.0.0/16.
Egress firewall rules are evaluated against the instance's network tags, and the priority-1000 deny explicitly blocks traffic from 'app-tier' instances to 10.1.0.0/16. Because the web subnet lacks that tag, its traffic passes, while the app tier is dropped before reaching the VPN tunnel.
The Cloud Router is not advertising the 10.0.2.0/24 subnet to on-premises.
Want more Implementing a Virtual Private Cloud practice?
Practice this domainThe PCNE exam has 60 questions and must be completed in 120 minutes. The passing score is 720/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 7 domains: Configuring Network Services, Managing, Monitoring, and Optimising Network Operations, Implementing Hybrid Interconnectivity, Designing, Planning, and Prototyping a GCP Network, Implementing VPC Instances, Implementing network security, Implementing a Virtual Private Cloud. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Google Cloud PCNE exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.