Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam Professional Cloud Architect All Questions

View all questions & answers for the Professional Cloud Architect exam

Exam Professional Cloud Architect topic 1 question 77 discussion

Actual exam question from Google's Professional Cloud Architect
Question #: 77
Topic #: 1
[All Professional Cloud Architect Questions]

You want to establish a Compute Engine application in a single VPC across two regions. The application must communicate over VPN to an on-premises network.
How should you deploy the VPN?

  • A. Use VPC Network Peering between the VPC and the on-premises network.
  • B. Expose the VPC to the on-premises network using IAM and VPC Sharing.
  • C. Create a global Cloud VPN Gateway with VPN tunnels from each region to the on-premises peer gateway.
  • D. Deploy Cloud VPN Gateway in each region. Ensure that each region has at least one VPN tunnel to the on-premises peer gateway.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Googler2
Highly Voted 4 years, 7 months ago
It can't be -A - VPC Network Peering only allows private RFC 1918 connectivity across two Virtual Private Cloud (VPC) networks. In this example is one VPC with on-premise network https://cloud.google.com/vpc/docs/vpc-peering It is not definitely - B - Can't be It is not C - Because Cloud VPN gateways and tunnels are regional objects, not global So, it the answer is D - https://cloud.google.com/vpn/docs/how-to/creating-static-vpns
upvoted 44 times
amxexam
3 years, 2 months ago
Why not A? https://cloud.google.com/vpc/docs/vpc-peering#benefits_of_exchanging_custom_routes The second use case is exactly what is in the question. Don't get the argument about RFC 1918. Will go with A
upvoted 1 times
ochanz
2 years, 11 months ago
https://cloud.google.com/vpc/docs/vpc-peering allows internal IP address connectivity across two VPC so A is not the answer as the on premise network need to use public IP. cmiiw
upvoted 4 times
...
AdityaGupta
1 year, 1 month ago
The question clearly asks us to use VPN.
upvoted 2 times
...
...
AzureDP900
2 years, 1 month ago
Agreed with D.
upvoted 1 times
...
...
TaherShaker
Highly Voted 4 years ago
Just Passed my exam and I answered (D) for this question
upvoted 20 times
M_Asep
2 years, 11 months ago
sound promising dude
upvoted 3 times
...
Sur_Nikki
1 year, 6 months ago
IS the Exam Idea questions enough dude, for passing this exam?
upvoted 3 times
...
...
ccpmad
Most Recent 5 months ago
Selected Answer: D
Option C: Create a global VPN gateway and establish VPN tunnels from each region to the on-premises peer gateway. This suggests that a single global VPN gateway manages the tunnels from both regions. Option D: Deploy a VPN gateway in each region and ensure that each region has at least one VPN tunnel to the on-premises peer gateway. This indicates that each region has its own VPN gateway. >Option D ensures that there is a VPN gateway in each region, providing greater redundancy. If a gateway in one region fails, the gateway in the other region remains operational.
upvoted 1 times
...
santoshchauhan
8 months ago
Selected Answer: C
Global Cloud VPN Gateway: This feature allows for the creation of a single VPN gateway that can serve multiple regions within the same VPC network. By creating a global VPN gateway, you can efficiently manage VPN connections from all regions of your VPC to your on-premises network. Simplicity and Efficiency: Using a global gateway simplifies the configuration and management of VPN connections as opposed to maintaining separate regional VPN gateways. It centralizes the VPN endpoint on the Google Cloud side, reducing the complexity of the network setup. Reliable and Secure Communication: The global Cloud VPN Gateway allows for secure, encrypted tunnels between Google Cloud and the on-premises network, ensuring that the application’s inter-regional and on-premises communications are secure.
upvoted 2 times
...
salvo007
10 months, 4 weeks ago
Selected Answer: D
C is wrong. A global vpn is a single region resource. https://cloud.google.com/network-connectivity/docs/vpn/how-to/creating-ha-vpn?hl=it gcloud compute vpn-gateways create GW_NAME \ --network=NETWORK \ --region=REGION \ --stack-type=IP_STACK so D is the answer
upvoted 1 times
...
gcmrjbr
11 months ago
It´s option C! So, while the VPN Gateway itself is a regional resource, its scope can be effectively global as it can serve resources across different regions within the same Virtual Private Cloud (VPC). This is why it’s sometimes referred to as a ‘global’ service in the context of its functionality, even though strictly speaking, it’s a regional resource.
upvoted 2 times
...
AdityaGupta
1 year, 1 month ago
Selected Answer: D
Each Cloud VPN gateway is a regional resource that uses one or more regional external IP addresses. A Cloud VPN gateway can connect to a peer VPN gateway.
upvoted 2 times
...
LaxmanTiwari
1 year, 6 months ago
It can't be -A - VPC Network Peering only allows private RFC 1918 connectivity across two Virtual Private Cloud (VPC) networks. In this example is one VPC with on-premise network https://cloud.google.com/vpc/docs/vpc-peering It is not definitely - B - Can't be It is not C - Because Cloud VPN gateways and tunnels are regional objects, not global So, it the answer is D - https://cloud.google.com/vpn/docs/how-to/creating-static-vpn
upvoted 3 times
...
vvkds
1 year, 10 months ago
Selected Answer: D
D looks fine.
upvoted 1 times
...
oms_muc
1 year, 11 months ago
Selected Answer: D
As HA isn't required, why do we need two VPN gateways?
upvoted 2 times
...
megumin
2 years ago
Selected Answer: D
D is ok
upvoted 1 times
...
Mahmoud_E
2 years, 1 month ago
Selected Answer: D
D is the correct answer, in order to do A you will need VPN., or interconnect
upvoted 1 times
...
zr79
2 years, 1 month ago
there is two VPN: 1. classic VPN 2. HA VPN
upvoted 1 times
...
DrishaS4
2 years, 3 months ago
Selected Answer: D
Cloud VPN Gateway is a regional service, not global.
upvoted 4 times
...
elaineshi
2 years, 6 months ago
Why not C? services across regions can communicate to each other, VPN only connects to the closet region, and all the VPC shall be connected if firewall's set.
upvoted 2 times
...
haroldbenites
2 years, 11 months ago
Go for D. Cloud VPN Gateway is regional. NOt Global gcloud compute vpn-gateways create GW_NAME \ --network=NETWORK \ --region=REGION
upvoted 2 times
...
vincy2202
3 years ago
D is the correct answer
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...