QuestionQ1
Configuring, implementing and managing a cloud network security solutionYou are designing a packet-mirroring policy as part of the network security architecture for your gaming workload. Your infrastructure is in the us-west2 region and spans several zones: us-west2-a, us-west2-b, and us-west2-c. The infrastructure runs a web-based application on TCP ports 80 and 443, along with other game servers that use the UDP protocol. You need to deploy packet-mirroring policies and collector instances to monitor web-application traffic while minimizing inter-zonal network-egress costs.
Following Google-recommended practices, how should you deploy the packet-mirroring policies and collector instances?
QuestionQ2
Designing and planning a Google Cloud Virtual Private Cloud (VPC) networkYou need to create a GKE cluster in an existing VPC that can be accessed from on-premises. You must satisfy these requirements:
- IP ranges for Pods and Services must be as small as possible.
- The nodes and master must not be accessible from the internet.
- You must be able to run
kubectlcommands from on-premises subnets to manage the cluster.
How should you create the GKE cluster?
Community Discussion
QuestionQ3
Managing, monitoring, and troubleshooting network operationsYou have set up an HTTP(S) load-balanced service and need to confirm that the backend instances are responding correctly.
How should you configure the health check?
Community Discussion
QuestionQ4
Configuring, implementing and managing a cloud network security solutionYour company uses web application firewall (WAF) capabilities from a third-party cloud WAF provider. The WAF provider proxies every HTTPS connection from internet clients, applies security policies, and then opens a new HTTPS connection to the public IP address of your global Application Load Balancer in Google Cloud. Your Google Cloud workloads are the backends for this global Application Load Balancer. Cloud Am1or is currently not configured.
You need to create a Cloud Armor security policy that blocks sessions originating from internet clients whose source IP addresses belong to the IP_RANGE_BLOCK IP range. The block must be enforced by the Cloud Armor security policy; the third-party cloud WAF provider will not perform it. What should you do?
Community Discussion
QuestionQ5
Configuring and implementing hybrid and multi-cloud network interconnectivityA multi-region VPC has long used HA VPN in "region 1" to connect to your corporate network. You plan to add two 10 Gbps Dedicated Interconnect connections and VLAN attachments in "region 2" to connect to that same corporate network. You must plan VPC-to-corporate-network connectivity so that traffic uses the Dedicated Interconnect connections as the primary path and the HA VPN as the secondary path. What should you do?
Community Discussion