[2022年07月]更新のGoogle Professional-Cloud-Network-Engineer試験基本問題には解答が付きます [Q23-Q47]

Rate this post

[2022年07月]更新のGoogle Professional-Cloud-Network-Engineer試験基本問題には解答が付きます

2022年最新の実際に出るGoogle Professional-Cloud-Network-Engineer試験問題集と解答

Google Professional-Cloud-Network-Engineer 認定試験の出題範囲:

トピック 出題範囲
トピック 1
  • ネットワークリソースの最適化
  • ロードバランサーとCDNの場所
  • ハイブリッドネットワークの設計。相互接続、フェイルオーバー、およびディザスタリカバリ戦略の使用に関する考慮事項
トピック 2
  • 全体的なネットワークアーキテクチャの設計。考慮事項ハイブリッド接続、コンテナネットワーク、高可用性のオプション
トピック 3
  • GCP仮想プライベートクラウド(VPC)の実装
  • 共有VPCの作成と、他のプロジェクトとサブネットを共有する方法の説明
トピック 4
  • ネットワーク運用の管理と監視
  • Google KubernetesEngineのコンテナIPアドレス指定計画の設計
トピック 5
  • 共有vs.スタンドアロンVPC相互接続アクセス
  • 適切な負荷分散オプションの選択
トピック 6
  • Google KubernetesEngineクラスターの構成と保守
  • Google KubernetesEngineクラスターの構成と保守

 

23、You have created a firewall with rules that only allow traffic over HTTP, HTTPS, and SSH ports. While testing, you specifically try to reach the server over multiple ports and protocols; however, you do not see any denied connections in the firewall logs. You want to resolve the issue.
What should you do?

 
 
 
 

24、You need to restrict access to your Google Cloud load-balanced application so that only specific IP addresses can connect.
What should you do?

 
 
 
 

25、An application development team believes their current logging tool will not meet their needs for their new cloud-based product. They want a better tool to capture errors and help them analyze their historical log data. You want to help them find a solution that meets their needs, what should you do?

 
 
 
 

26、You need to establish network connectivity between three Virtual Private Cloud networks, Sales, Marketing, and Finance, so that users can access resources in all three VPCs. You configure VPC peering between the Sales VPC and the Finance VPC. You also configure VPC peering between the Marketing VPC and the Finance VPC. After you complete the configuration, some users cannot connect to resources in the Sales VPC and the Marketing VPC. You want to resolve the problem.
What should you do?

 
 
 
 

27、In your company, two departments with separate GCP projects (code-dev and data-dev) in the same organization need to allow full cross-communication between all of their virtual machines in GCP. Each department has one VPC in its project and wants full control over their network. Neither department intends to recreate its existing computing resources. You want to implement a solution that minimizes cost.
Which two steps should you take? (Choose two.)

 
 
 
 
 

28、You are migrating to Cloud DNS and want to import your BIND zone file.
Which command should you use?

 
 
 
 

29、Your company just completed the acquisition of Altostrat (a current GCP customer). Each company has a separate organization in GCP and has implemented a custom DNS solution. Each organization will retain its current domain and host names until after a full transition and architectural review is done in one year. These are the assumptions for both GCP environments.
* Each organization has enabled full connectivity between all of its projects by using Shared VPC.
* Both organizations strictly use the 10.0.0.0/8 address space for their instances, except for bastion hosts (for accessing the instances) and load balancers for serving web traffic.
* There are no prefix overlaps between the two organizations.
* Both organizations already have firewall rules that allow all inbound and outbound traffic from the 10.0.0.0/8 address space.
* Neither organization has Interconnects to their on-premises environment.
You want to integrate networking and DNS infrastructure of both organizations as quickly as possible and with minimal downtime.
Which two steps should you take? (Choose two.)

 
 
 
 
 

30、Your company’s web server administrator is migrating on-premises backend servers for an application to GCP.
Libraries and configurations differ significantly across these backend servers. The migration to GCP will be lift- and-shift, and all requests to the servers will be served by a single network load balancer frontend. You want to use a GCP-native solution when possible.
How should you deploy this service in GCP?

 
 
 
 

31、You are trying to update firewall rules in a shared VPC for which you have been assigned only Network Admin permissions. You cannot modify the firewall rules. Your organization requires using the least privilege necessary.
Which level of permissions should you request?

 
 
 
 

32、Your company has a security team that manages firewalls and SSL certificates. It also has a networking team that manages the networking resources. The networking team needs to be able to read firewall rules, but should not be able to create, modify, or delete them.
How should you set up permissions for the networking team?

 
 
 
 

33、You want to use Cloud Interconnect to connect your on-premises network to a GCP VPC. You cannot meet Google at one of its point-of-presence (POP) locations, and your on-premises router cannot run a Border Gateway Protocol (BGP) configuration.
Which connectivity model should you use?

 
 
 
 

34、You want to set up two Cloud Routers so that one has an active Border Gateway Protocol (BGP) session, and the other one acts as a standby.
Which BGP attribute should you use on your on-premises router?

 
 
 
 

35、You want to create a service in GCP using IPv6.
What should you do?

 
 
 
 

36、You want to create a service in GCP using IPv6.
What should you do?

 
 
 
 

37、You have deployed a proof-of-concept application by manually placing instances in a single Compute Engine zone. You are now moving the application to production, so you need to increase your application availability and ensure it can autoscale.
How should you provision your instances?

 
 
 
 

38、Your end users are located in close proximity to us-east1 and europe-west1. Their workloads need to communicate with each other. You want to minimize cost and increase network efficiency.
How should you design this topology?

 
 
 
 

39、You are using a third-party next-generation firewall to inspect traffic. You created a custom route of 0.0.0.0/0 to route egress traffic to the firewall. You want to allow your VPC instances without public IP addresses to access the BigQuery and Cloud Pub/Sub APIs, without sending the traffic through the firewall.
Which two actions should you take? (Choose two.)

 
 
 
 
 

40、You create a Google Kubernetes Engine private cluster and want to use kubectl to get the status of the pods. In one of your instances you notice the master is not responding, even though the cluster is up and running.
What should you do to solve the problem?

 
 
 
 

41、You need to centralize the Identity and Access Management permissions and email distribution for the WebServices Team as efficiently as possible.
What should you do?

 
 
 
 

42、You are designing a Google Kubernetes Engine (GKE) cluster for your organization. The current cluster size is expected to host 10 nodes, with 20 Pods per node and 150 services. Because of the migration of new services over the next 2 years, there is a planned growth for 100 nodes, 200 Pods per node, and 1500 services. You want to use VPC-native clusters with alias IP ranges, while minimizing address consumption.
How should you design this topology?

 
 
 
 

43、Your developer group works on a set of VM’s frequently throughout the day. To save costs, you terminate the VM when it is not in use. However, you need to preserve the contents of the disk when the VM is terminated so users can resume where they left off when a new one is created.
What is the most cost-effective way to do? (Choose two)

 
 
 
 

44、You have recently been put in charge of managing identity and access management for your organization. You have several projects and want to use scripting and automation wherever possible. You want to grant the editor role to a project member.
Which two methods can you use to accomplish this? (Choose two.)

 
 
 
 
 

45、You are deploying a global external TCP load balancing solution and want to preserve the source IP address of the original layer 3 payload.
Which type of load balancer should you use?

 
 
 
 

46、You decide to set up Cloud NAT. After completing the configuration, you find that one of your instances is not using the Cloud NAT for outbound NAT.
What is the most likely cause of this problem?

 
 
 
 

47、You have created an HTTP(S) load balanced service. You need to verify that your backend instances are responding properly.
How should you configure the health check?

 
 
 
 

合格保証付きのGoogle Cloud Platform Professional-Cloud-Network-Engineer試験問題集:https://www.passtest.jp/Google/Professional-Cloud-Network-Engineer-shiken.html

         

Related Links: www.stes.tyc.edu.tw myportal.utt.edu.tt myportal.utt.edu.tt myportal.utt.edu.tt myportal.utt.edu.tt myportal.utt.edu.tt

コメントを残す

メールアドレスが公開されることはありません。 ※ が付いている欄は必須項目です

Enter the text from the image below