You create a Google Kubernetes Engine private cluster and want to use kubectl to get the status of the pods. In one of your
instances you notice the master is not responding, even though the cluster is up and running.
What should you do to solve the problem?
C
You create multiple Compute Engine virtual machine instances to be used at TFTP servers.
Which type of load balancer should you use?
D
You are using a third-party next-generation firewall to inspect traffic. You created a custom route of 0.0.0.0/0 to route egress
traffic to the firewall. You want to allow your VPC instances without public IP addresses to access the BigQuery and Cloud
Pub/Sub APIs, without sending the traffic through the firewall.
Which two actions should you take? (Choose two.)
C E
Explanation:
Reference: https://cloud.google.com/vpc/docs/private-access-options
You have a storage bucket that contains two objects. Cloud CDN is enabled on the bucket, and both objects have been
successfully cached. Now you want to make sure that one of the two objects will not be cached anymore, and will always be
served to the internet directly from the origin.
What should you do?
A
Explanation:
Reference: https://developers.google.com/web/ilt/pwa/caching-files-with-service-worker
Your company has a security team that manages firewalls and SSL certificates. It also has a networking team that manages
the networking resources. The networking team needs to be able to read firewall rules, but should not be able to create,
modify, or delete them.
How should you set up permissions for the networking team?
B
Explanation:
Reference: https://cloud.google.com/compute/docs/access/iam
You work for a university that is migrating to GCP.
These are the cloud requirements:
On-premises connectivity with 10 Gbps
Lowest latency access to the cloud
Centralized Networking Administration Team
New departments are asking for on-premises connectivity to their projects. You want to deploy the most cost-efficient
interconnect solution for connecting the campus to Google Cloud.
What should you do?
A
You are adding steps to a working automation that uses a service account to authenticate. You need to drive the automation
the ability to retrieve files from a Cloud Storage bucket. Your organization requires using the least privilege possible.
What should you do?
B
Explanation:
Reference: https://cloud.google.com/compute/docs/access/iam
You want to set up two Cloud Routers so that one has an active Border Gateway Protocol (BGP) session, and the other one
acts as a standby.
Which BGP attribute should you use on your on-premises router?
D
Explanation:
Reference: https://cloud.google.com/router/docs/concepts/overview
You need to define an address plan for a future new GKE cluster in your VPC. This will be a VPC native cluster, and the
default Pod IP range allocation will be used. You must pre-provision all the needed VPC subnets and their respective IP
address ranges before cluster creation. The cluster will initially have a single node, but it will be scaled to a maximum of
three nodes if necessary. You want to allocate the minimum number of Pod IP addresses.
Which subnet mask should you use for the Pod IP address range?
D
Explanation:
Reference: https://cloud.google.com/kubernetes-engine/docs/how-to/alias-ips
Your on-premises data center has 2 routers connected to your GCP through a VPN on each router. All applications are
working correctly; however, all of the traffic is passing across a single VPN instead of being load-balanced across the 2
connections as desired.
During troubleshooting you find:
Each on-premises router is configured with the same ASN.
Each on-premises router is configured with the same routes and priorities.
Both on-premises routers are configured with a VPN connected to a single Cloud Router.
The VPN logs have no-proposal-chosen lines when the VPNs are connecting.
BGP session is not established between one on-premises router and the Cloud Router.
What is the most likely cause of this problem?
C
Your company just completed the acquisition of Altostrat (a current GCP customer). Each company has a separate
organization in GCP and has implemented a custom DNS solution. Each organization will retain its current domain and host
names until after a full transition and architectural review is done in one year. These are the assumptions for both GCP
environments.
Each organization has enabled full connectivity between all of its projects by using Shared VPC.
Both organizations strictly use the 10.0.0.0/8 address space for their instances, except for bastion hosts (for accessing the
instances) and load balancers for serving web traffic.
There are no prefix overlaps between the two organizations.
Both organizations already have firewall rules that allow all inbound and outbound traffic from the 10.0.0.0/8 address
space.
Neither organization has Interconnects to their on-premises environment.
You want to integrate networking and DNS infrastructure of both organizations as quickly as possible and with minimal
downtime.
Which two steps should you take? (Choose two.)
C D
You need to configure a static route to an on-premises resource behind a Cloud VPN gateway that is configured for policy-
based routing using the gcloud command.
Which next hop should you choose?
C
Explanation:
Reference: https://cloud.google.com/vpn/docs/how-to/creating-static-vpns
Your on-premises data center has 2 routers connected to your Google Cloud environment through a VPN on each router. All
applications are working correctly; however, all of the traffic is passing across a single VPN instead of being load-balanced
across the 2 connections as desired.
During troubleshooting you find:
Each on-premises router is configured with a unique ASN.
Each on-premises router is configured with the same routes and priorities.
Both on-premises routers are configured with a VPN connected to a single Cloud Router.
BGP sessions are established between both on-premises routers and the Cloud Router.
Only 1 of the on-premises routers routes are being added to the routing table.
What is the most likely cause of this problem?
D
You want to implement an IPSec tunnel between your on-premises network and a VPC via Cloud VPN. You need to restrict
reachability over the tunnel to specific local subnets, and you do not have a device capable of speaking Border Gateway
Protocol (BGP).
Which routing option should you choose?
A
Explanation:
Reference: https://cloud.google.com/vpn/docs/concepts/overview
You want to use Cloud Interconnect to connect your on-premises network to a GCP VPC. You cannot meet Google at one of
its point-of-presence (POP) locations, and your on-premises router cannot run a Border Gateway Protocol (BGP)
configuration.
Which connectivity model should you use?
B
Explanation:
Reference: https://cloud.google.com/interconnect/docs/support/faq