Your organization has Compute Engine instances in us-east1, us-west2, and us-central1. Your organization also has an existing Cloud Interconnect physical connection in the East Coast of the United States with a single VLAN attachment and Cloud Router in us-east1. You need to provide a design with high availability and ensure that if a region goes down, you still have access to all your other Virtual Private Cloud (VPC) subnets. You need to accomplish this in the most cost-effective manner possible. What should you do?
Google Prof Cloud Network - pt 8

Quiz
•
Computers
•
University
•
Medium
Katheryne Pierce
Used 1+ times
FREE Resource
15 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
5 mins • 1 pt
1. Configure your VPC routing in regional mode. 2. Add an additional Cloud Interconnect VLAN attachment in the us-east1 region, and configure a Cloud Router in us-east1.
1. Configure your VPC routing in global mode. 2. Add an additional Cloud Interconnect VLAN attachment in the us-east1 region, and configure a Cloud Router in us-east1.
1. Configure your VPC routing in global mode. 2. Add an additional Cloud Interconnect VLAN attachment in the us-west2 region, and configure a Cloud Router in us-west2.
1. Configure your VPC routing in regional mode. 2. Add additional Cloud Interconnect VLAN attachments in the us-west2 and us-central1 regions, and configure Cloud Routers in us-west2 and us-central1.
2.
MULTIPLE CHOICE QUESTION
5 mins • 1 pt
You recently configured Google Cloud Armor security policies to manage traffic to your application. You discover that Google Cloud Armor is incorrectly blocking some traffic to your application. You need to identity the web application firewall (WAF) rule that is incorrectly blocking traffic. What should you do?
Enable firewall logs, and view the logs in Firewall Insights.
Enable HTTP(S) Load Balancing logging with sampling rate equal to 1, and view the logs in Cloud Logging.
Enable VPC Flow Logs, and view the logs in Cloud Logging.
Enable Google Cloud Armor audit logs, and view the logs on the Activity page in the Google Cloud Console.
3.
MULTIPLE CHOICE QUESTION
5 mins • 1 pt
You are the Organization Admin for your company. One of your engineers is responsible for setting up multiple host projects across multiple folders and sharing subnets with service projects. You need to enable the engineer's Identity and Access Management (IAM) configuration to complete their task in the fewest number of steps. What should you do?
Set up the engineer with Compute Shared VPC Admin IAM role at the folder level.
Set up the engineer with Compute Shared VPC Admin IAM role at the organization level.
Set up the engineer with Compute Shared VPC Admin IAM role and Project IAM Admin role at the folder level.
Set up the engineer with Compute Shared VPC Admin IAM role and Project IAM Admin role at the organization level.
4.
MULTIPLE CHOICE QUESTION
5 mins • 1 pt
You recently deployed Compute Engine instances in regions us-west1 and us-east1 in a Virtual Private Cloud (VPC) with default routing configurations. Your company security policy mandates that virtual machines (VMs) must not have public IP addresses attached to them. You need to allow your instances to fetch updates from the internet while preventing external access. What should you do?
Create a Cloud NAT gateway and Cloud Router in both us-west1 and us-east1.
Create a single global Cloud NAT gateway and global Cloud Router in the VPC.
Change the instances’ network interface external IP address from None to Ephemeral.
Create a firewall rule that allows egress to destination 0.0.0.0/0.
5.
MULTIPLE CHOICE QUESTION
5 mins • 1 pt
You are designing a new global application using Compute Engine instances that will be exposed by a global HTTP(S) load balancer. You need to secure your application from distributed denial-of-service and application layer (layer 7) attacks. What should you do?
Configure VPC Service Controls and create a secure perimeter. Define fine-grained perimeter controls and enforce that security posture across your Google Cloud services and projects.
Configure a Google Cloud Armor security policy in your project, and attach it to the backend service to secure the application.
Configure VPC firewall rules to protect the Compute Engine instances against distributed denial-of-service attacks.
Configure hierarchical firewall rules for the global HTTP(S) load balancer public IP address at the organization level.
6.
MULTIPLE CHOICE QUESTION
5 mins • 1 pt
Your organization's security policy requires that all internet-bound traffic return to your on-premises data center through HA VPN tunnels before egressing to the internet, while allowing virtual machines (VMs) to leverage private Google APIs using private virtual IP addresses 199.36.153.4/30. You need to configure the routes to enable these traffic flows. What should you do?
Configure a custom route 0.0.0.0/0 with a priority of 500 whose next hop is the default internet gateway. Configure another custom route 199.36.153.4/30 with priority of 1000 whose next hop is the VPN tunnel back to the on-premises data center.
Configure a custom route 0.0.0.0/0 with a priority of 1000 whose next hop is the internet gateway. Configure another custom route 199.36.153.4/30 with a priority of 500 whose next hop is the VPN tunnel back to the onpremises data center.
Announce a 0.0.0.0/0 route from your on-premises router with a MED of 1000. Configure a custom route 199.36.153.4/30 with a priority of 1000 whose next hop is the default internet gateway.
Announce a 0.0.0.0/0 route from your on-premises router with a MED of 500. Configure another custom route 199.36.153.4/30 with a priority of 1000 whose next hop is the VPN tunnel back to the on-premises data center.
7.
MULTIPLE CHOICE QUESTION
5 mins • 1 pt
Your company has defined a resource hierarchy that includes a parent folder with subfolders for each department. Each department defines their respective project and VPC in the assigned folder and has the appropriate permissions to create Google Cloud firewall rules. The VPCs should not allow traffic to flow between them. You need to block all traffic from any source, including other VPCs, and delegate only the intra-VPC firewall rules to the respective departments. What should you do?
Create a VPC firewall rule in each VPC to block traffic from any source, with priority 0.
Create a VPC firewall rule in each VPC to block traffic from any source, with priority 1000.
Create two hierarchical firewall policies per department's folder with two rules in each: a high-priority rule that matches traffic from the private CIDRs assigned to the respective VPC and sets the action to allow, and another lower-priority rule that blocks traffic from any other source.
Create two hierarchical firewall policies per department's folder with two rules in each: a high-priority rule that matches traffic from the private CIDRs assigned to the respective VPC and sets the action to goto_next, and another lower-priority rule that blocks traffic from any other source.
Create a free account and access millions of resources
Similar Resources on Quizizz
15 questions
Wireless Networking Configuration

Quiz
•
University
20 questions
Uji Pengetahuan Jaringan Komputer

Quiz
•
9th Grade - University
15 questions
IC3 GS6 Level 1 Domain 2 Lesson 1

Quiz
•
6th Grade - University
20 questions
Cisco Configuration Commands Quizs

Quiz
•
University
20 questions
Networking Quiz

Quiz
•
11th Grade - University
10 questions
Intro to Linux Network Management Quiz

Quiz
•
University
20 questions
Module 7

Quiz
•
University
20 questions
Fundamen AWS Cloud

Quiz
•
University
Popular Resources on Quizizz
15 questions
Character Analysis

Quiz
•
4th Grade
17 questions
Chapter 12 - Doing the Right Thing

Quiz
•
9th - 12th Grade
10 questions
American Flag

Quiz
•
1st - 2nd Grade
20 questions
Reading Comprehension

Quiz
•
5th Grade
30 questions
Linear Inequalities

Quiz
•
9th - 12th Grade
20 questions
Types of Credit

Quiz
•
9th - 12th Grade
18 questions
Full S.T.E.A.M. Ahead Summer Academy Pre-Test 24-25

Quiz
•
5th Grade
14 questions
Misplaced and Dangling Modifiers

Quiz
•
6th - 8th Grade