Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam Professional Cloud Architect All Questions

View all questions & answers for the Professional Cloud Architect exam

Exam Professional Cloud Architect topic 1 question 150 discussion

Actual exam question from Google's Professional Cloud Architect
Question #: 150
Topic #: 1
[All Professional Cloud Architect Questions]

Your team needs to create a Google Kubernetes Engine (GKE) cluster to host a newly built application that requires access to third-party services on the internet.
Your company does not allow any Compute Engine instance to have a public IP address on Google Cloud. You need to create a deployment strategy that adheres to these guidelines. What should you do?

  • A. Configure the GKE cluster as a private cluster, and configure Cloud NAT Gateway for the cluster subnet.
  • B. Configure the GKE cluster as a private cluster. Configure Private Google Access on the Virtual Private Cloud (VPC).
  • C. Configure the GKE cluster as a route-based cluster. Configure Private Google Access on the Virtual Private Cloud (VPC).
  • D. Create a Compute Engine instance, and install a NAT Proxy on the instance. Configure all workloads on GKE to pass through this proxy to access third-party services on the Internet.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ACE_ASPIRE
Highly Voted 3 years, 2 months ago
Cloud NAT is the correct answer
upvoted 32 times
...
RitwickKumar
Highly Voted 2 years, 3 months ago
Selected Answer: A
** Admins: More than 60% of the answers you have selected are wrong. Please correct them ASAP. I must appreciate community here for taking out time to share their perspective and help fellow learners. "B" can never be an answer here as the Private Google Access enables internal access to Google APIs only whereas in question the ask is "access to third-party services on the internet"
upvoted 26 times
ArtistS
1 year ago
If they provide the correct answer, you will never see this website any more
upvoted 7 times
Sephethus
5 months, 1 week ago
True, but then if it were shut down literally nobody could pass this ridiculous test where half the questions are so badly worded and confusing with debatable options.
upvoted 1 times
...
...
jlambdan
1 year, 7 months ago
This is most likely on purpose. Otherwise google will do something in order for the exam dump to be shutdown.
upvoted 13 times
...
...
19040e5
Most Recent 6 months, 1 week ago
Selected Answer: A
Cloud NAT, Private Service Connect is for Google API Access.
upvoted 1 times
...
kahinah
8 months, 3 weeks ago
Selected Answer: A
Cloud NAT to access to the internet
upvoted 1 times
...
didek1986
10 months, 1 week ago
Selected Answer: A
It is A
upvoted 1 times
...
techtitan
12 months ago
Selected Answer: A
Needs Nat to connect to 3rd party apps
upvoted 1 times
...
6b13108
12 months ago
B is only part of the solution, but needs Cloud Nat to get access on the internet with third-party services, then the correct answer is A . See doc: https://cloud.google.com/kubernetes-engine/docs/concepts/private-cluster-concept
upvoted 1 times
...
tamj123
1 year, 1 month ago
Selected Answer: A
go for Cloud NAT
upvoted 1 times
...
RaviRS
1 year, 2 months ago
Selected Answer: A
I am not sure who's writing these answers Private Google Access is useful for allowing Google Cloud resources, including GKE clusters, to access Google services without public IPs, but it doesn't provide access to third-party services on the internet.
upvoted 2 times
...
[Removed]
1 year, 5 months ago
Selected Answer: A
Cloud NAT A
upvoted 1 times
...
DS2023
1 year, 6 months ago
Selected Answer: A
Cloud NAT allows the resources in private subnet to access the internet—for updates, patching, config management, and more—in a controlled and efficient manner.
upvoted 1 times
LaxmanTiwari
1 year, 5 months ago
Yeah agree as GKE admin
upvoted 1 times
...
...
DS2023
1 year, 6 months ago
Selected Answer: A. Cloud NAT allows the resources in private subnet to access the internet—for updates, patching, config management, and more—in a controlled and efficient manner.
upvoted 1 times
...
dbsmk
1 year, 7 months ago
A. https://cloud.google.com/kubernetes-engine/docs/how-to/private-clusters#workloads_on_private_clusters_unable_to_access_internet
upvoted 3 times
...
JC0926
1 year, 8 months ago
Selected Answer: B
Private Google Access allows resources in a VPC network to access Google Cloud services without an external IP address. By configuring the GKE cluster as a private cluster, the nodes and services inside the cluster will not have a public IP address, and only resources within the VPC network will be able to communicate with them. With Private Google Access enabled, the GKE cluster can access third-party services on the internet via Google APIs and services without requiring a public IP address. Therefore, the correct option is: B. Configure the GKE cluster as a private cluster. Configure Private Google Access on the Virtual Private Cloud (VPC).
upvoted 1 times
...
r1ck
1 year, 9 months ago
answer should be "B" https://cloud.google.com/vpc/docs/private-access-options
upvoted 2 times
...
examch
1 year, 10 months ago
Selected Answer: A
A is the correct answer, Granting private nodes outbound internet access To provide outbound internet access for your private nodes, such as to pull images from an external registry, use Cloud NAT to create and configure a Cloud Router. Cloud NAT lets private clusters establish outbound connections over the internet to send and receive packets. The Cloud Router allows all your nodes in the region to use Cloud NAT for all primary and alias IP ranges. It also automatically allocates the external IP addresses for the NAT gateway. For instructions to create and configure a Cloud Router, refer to Create a Cloud NAT configuration using Cloud Router in the Cloud NAT documentation. https://cloud.google.com/kubernetes-engine/docs/how-to/private-clusters#private-nodes-outbound
upvoted 3 times
...
surajkrishnamurthy
1 year, 11 months ago
Selected Answer: A
A is the correct answer
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...