Migrate from Cloud VPN to Dedicated Interconnect Without Downtime
A company currently uses Cloud VPN with dynamic routing to connect to Google Cloud. They want to migrate to Dedicated Interconnect without downtime. Which THREE steps should they take to achieve a seamless migration? (Choose three.)
Quick Answer
The answer is to create a new VLAN attachment and attach it to the existing Cloud Router to peer with both VPN and Interconnect. This is correct because the Cloud Router supports dynamic routing with multiple BGP sessions simultaneously, allowing both the Cloud VPN tunnel and the Dedicated Interconnect VLAN attachment to exchange routes concurrently. By establishing BGP peering for both connections on the same router, you can gradually shift traffic by adjusting route priorities, ensuring zero packet loss during the migration. On the Google Professional Cloud Network Engineer exam, this scenario tests your understanding of hybrid connectivity and route advertisement control; a common trap is assuming you must decommission the VPN first or create a separate router. Remember the memory tip: "Same router, dual peers—migrate without tears."
⚠ Common exam trap
Google Cloud often tests the misconception that firewall rules must be updated when migrating connectivity types, but in reality, the migration is driven by BGP route preference adjustments, not firewall changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Order and provision the Dedicated Interconnect
Ordering and provisioning the Dedicated Interconnect is the foundational step to establish the physical connection between the on-premises network and Google Cloud. Without this, no migration can occur. This involves working with a Google Cloud partner to ensure the cross-connect is completed and the VLAN attachments are created.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Order and provision the Dedicated Interconnect
Why this is correct
First, you need to have the physical connection ready.
- ✓
Configure BGP on the on-premises router for the Interconnect and start advertising routes
Why this is correct
BGP sessions must be established on the Interconnect to exchange routes.
- ✓
Create a new VLAN attachment and attach it to the existing Cloud Router to peer with both VPN and Interconnect
Why this is correct
Adding the Interconnect to the same Cloud Router allows both paths to be used and traffic to shift gradually.
- ✗
Decrease the BGP route priority (MED) on the VPN advertisements to make VPN less preferred
Why it's wrong here
You want to make Interconnect preferred, so decrease MED on Interconnect advertisements (lower MED is preferred). Decreasing MED on VPN would make VPN less preferred, which is correct, but typical approach is to set MED on Interconnect lower.
- ✗
Update on-premises firewall rules to allow traffic over the new Interconnect
Why it's wrong here
Firewall rules are on the GCP side; on-premises firewall is not managed by Google and indeed needs updating, but the question focuses on Google Cloud steps. However, 'configure BGP' is more directly a Cloud step. Option E is less central; typically firewall updates are needed but not part of the sequence to avoid downtime.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNE question from scratch — 961 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on PCNE
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company currently uses a site-to-site Cloud VPN (IPsec) to connect their on-premises network to a VPC. Due to growing bandwidth demands, they plan to migrate to Partner Interconnect using a supported service provider. They have ordered a 1 Gbps connection and the provider has indicated the VLAN attachment is ready. After creating the VLAN attachment and pairing it with a Cloud Router, the on-premises router sees the BGP session come up, but no traffic is forwarded over the interconnect. The Cloud VPN is still operational. What step is most likely missing?
medium- A.Create a VPC firewall rule to allow traffic on the VLAN attachment
- B.Add a firewall rule in the VPC allowing traffic from the on-premises IP ranges on the interconnect
- ✓ C.Adjust the BGP metric (MED) on the Cloud Router for the Partner Interconnect VLAN attachment to be lower than the VPN route
- D.Delete the Cloud VPN tunnel and gateway to force traffic over the interconnect
Why C: When both a Cloud VPN and a Partner Interconnect are connected to the same VPC, the Cloud Router will have multiple BGP routes for the same destination prefixes. By default, the VPN BGP session may have a lower MED (Multi-Exit Discriminator) or a higher local preference, causing traffic to prefer the VPN path. Lowering the MED on the VLAN attachment's BGP session makes the interconnect route more preferred, allowing traffic to be forwarded over the interconnect without deleting the VPN.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNE exam.