About the Exam

This certification is for network engineers and other cloud professionals who design, implement, and manage Google Cloud network infrastructure. It covers VPC design and implementation, managed network services, hybrid and multicloud connectivity, network operations, and cloud network security. Passing demonstrates that you can build and troubleshoot secure, scalable Google Cloud networks.

Exam Topics

  • Designing and planning a Google Cloud Virtual Private Cloud (VPC) network24%
  • Implementing a VPC network19%
  • Configuring managed network services16%
  • Configuring and implementing hybrid and multi-cloud network interconnectivity15%
  • Managing, monitoring, and troubleshooting network operations12%
  • Configuring, implementing and managing a cloud network security solution14%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 11, 2026 at 2:53 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Configuring, implementing and managing a cloud network security solution

You are designing a packet-mirroring policy as part of the network security architecture for your gaming workload. Your infrastructure is in the us-west2 region and spans several zones: us-west2-a, us-west2-b, and us-west2-c. The infrastructure runs a web-based application on TCP ports 80 and 443, along with other game servers that use the UDP protocol. You need to deploy packet-mirroring policies and collector instances to monitor web-application traffic while minimizing inter-zonal network-egress costs.

Following Google-recommended practices, how should you deploy the packet-mirroring policies and collector instances?

Explanation

Packet Mirroring can select sources using network tags and can filter by protocol, so tags can target only the web-server instances and a TCP filter captures their web traffic without mirroring UDP game-server traffic. Because mirrored traffic that travels between zones incurs egress charges, deploying a collector group in each source zone and directing that zone’s policy to its local collector group minimizes inter-zonal egress costs.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Designing and planning a Google Cloud Virtual Private Cloud (VPC) network

You need to create a GKE cluster in an existing VPC that can be accessed from on-premises. You must satisfy these requirements:

  • IP ranges for Pods and Services must be as small as possible.
  • The nodes and master must not be accessible from the internet.
  • You must be able to run kubectl commands from on-premises subnets to manage the cluster.

How should you create the GKE cluster?

Explanation

A VPC-native GKE cluster using user-managed secondary IP ranges lets the administrator define the Pod and Service CIDRs, including /24 ranges. Enabling the private control-plane endpoint disables external control-plane access, and master authorized networks can allow the required on-premises source CIDRs. A network proxy provides a controlled path for administrative access while keeping the cluster endpoints off the public internet.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Managing, monitoring, and troubleshooting network operations

You have set up an HTTP(S) load-balanced service and need to confirm that the backend instances are responding correctly.

How should you configure the health check?

Explanation

HTTP(S) health checks can target a specific request path and require an expected response string. A backend is considered healthy when it returns HTTP 200 and the expected string is found in the response body, so a stable health endpoint and known response content provide a reliable health signal.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Configuring, implementing and managing a cloud network security solution

Your company uses web application firewall (WAF) capabilities from a third-party cloud WAF provider. The WAF provider proxies every HTTPS connection from internet clients, applies security policies, and then opens a new HTTPS connection to the public IP address of your global Application Load Balancer in Google Cloud. Your Google Cloud workloads are the backends for this global Application Load Balancer. Cloud Am1or is currently not configured.

You need to create a Cloud Armor security policy that blocks sessions originating from internet clients whose source IP addresses belong to the IP_RANGE_BLOCK IP range. The block must be enforced by the Cloud Armor security policy; the third-party cloud WAF provider will not perform it. What should you do?

Explanation

A trusted upstream proxy causes origin.ip to contain the proxy’s address rather than the original internet client’s address. Configuring userIpRequestHeaders[] enables Cloud Armor to populate origin.user_ip from the client-IP header supplied by that proxy, so inIpRange(origin.user_ip, 'IP_RANGE_BLOCK') blocks the intended clients. A backend security policy is the appropriate policy type to attach to the backend service; edge security policies do not support origin.user_ip.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Configuring and implementing hybrid and multi-cloud network interconnectivity

A multi-region VPC has long used HA VPN in "region 1" to connect to your corporate network. You plan to add two 10 Gbps Dedicated Interconnect connections and VLAN attachments in "region 2" to connect to that same corporate network. You must plan VPC-to-corporate-network connectivity so that traffic uses the Dedicated Interconnect connections as the primary path and the HA VPN as the secondary path. What should you do?

Explanation

Global dynamic routing allows dynamically learned and advertised routes to be used across VPC regions. A Cloud Router BGP session’s base advertised priority becomes its MED value, and a lower MED has higher preference. Setting the Dedicated Interconnect VLAN attachments to 100 and the HA VPN to 20000 makes Dedicated Interconnect the preferred path while retaining HA VPN for failover; corresponding MED values on the on-premises routers maintain that preference in the opposite direction.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home