exam questions

Exam Professional Cloud Network Engineer All Questions

View all questions & answers for the Professional Cloud Network Engineer exam

Exam Professional Cloud Network Engineer topic 1 question 138 discussion

Actual exam question from Google's Professional Cloud Network Engineer
Question #: 138
Topic #: 1
[All Professional Cloud Network Engineer Questions]

Your company has a single Virtual Private Cloud (VPC) network deployed in Google Cloud with access from on-premises locations using Cloud Interconnect connections. Your company must be able to send traffic to Cloud Storage only through the Interconnect links while accessing other Google APIs and services over the public internet. What should you do?

  • A. Use the default public domains for all Google APIs and services.
  • B. Use Private Service Connect to access Cloud Storage, and use the default public domains for all other Google APIs and services.
  • C. Use Private Google Access, with restricted.googleapis.com virtual IP addresses for Cloud Storage and private.googleapis.com for all other Google APIs and services.
  • D. Use Private Google Access, with private.googleapis.com virtual IP addresses for Cloud Storage and restricted.googleapis.com virtual IP addresses for all other Google APIs and services.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
playpacman
Highly Voted 1 year, 4 months ago
B is is
upvoted 8 times
...
mohitms1996
Most Recent 6 days, 7 hours ago
Selected Answer: C
Analyzing Both Options 🔹 Option C: Private Google Access (restricted.googleapis.com) ✅ Google-recommended method for Cloud Storage over Interconnect. ✅ Easier to configure with VPC routes and DNS. ✅ Used when VMs only have private IPs and need access via Interconnect. ✅ More scalable and widely used. 🔹 Option B: Private Service Connect (PSC) for Cloud Storage ✅ Allows private, direct connections to specific Google services. ✅ Works for Cloud Storage but requires setting up PSC endpoints. ✅ More complex to configure than restricted.googleapis.com. What Do Google’s Official Docs Say? Google recommends using restricted.googleapis.com for Cloud Storage over Interconnect unless you specifically require PSC for other reasons. PSC is usually better suited for private connectivity to managed services like Cloud SQL, rather than Cloud Storage.
upvoted 1 times
...
RKS_2021
1 month ago
Selected Answer: C
C is correct Answer.
upvoted 1 times
RKS_2021
1 week, 2 days ago
B is correct, changing the answer to B.
upvoted 1 times
...
...
saraali
1 month, 2 weeks ago
Selected Answer: B
To ensure that traffic to Cloud Storage is routed through the Interconnect links while other Google APIs and services use the public internet, you can leverage Private Service Connect. This allows private access to services like Cloud Storage through your VPC while still enabling other services to use public IPs. Thus, B is the most suitable and effective approach.
upvoted 2 times
...
waelghaith
2 months, 3 weeks ago
Selected Answer: B
Based on this doc: https://cloud.google.com/vpc/docs/private-service-connect#endpoints "Private Service Connect endpoint can be used to access Google APIs such as Cloud Storage or BigQuery. This functionality is similar to Private Google Access, except that you can use your own internal IP addresses for endpoints." private.googleapis.com can't be reached through the internet since it's just reached within Google Cloud Networks
upvoted 2 times
...
ian_gcpca
2 months, 3 weeks ago
Selected Answer: C
private service connects can provide private access to CS but is generally for managed service only, not for access storage buckets directly. C - with restricted.googleapis.com virtual IP addresses for Cloud Storage --> send traffic to Cloud Storage only through the Interconnect links -private.googleapis.com for all other Google APIs and services --> for accessing other Google APIs and services over the public internet
upvoted 1 times
...
ZODOGAM
3 months ago
C Private Google Access: Private Google Access ensures that traffic to Google APIs and services originates from your private VPC network without requiring public IPs. restricted.googleapis.com: The restricted.googleapis.com domain ensures that traffic is routed exclusively over Cloud Interconnect for Google APIs and services, such as Cloud Storage. private.googleapis.com: The private.googleapis.com domain allows access to Google APIs and services over the public internet but only from private IP addresses in your VPC. Why This Works: Using restricted.googleapis.com for Cloud Storage ensures traffic to Cloud Storage is sent only through the Cloud Interconnect links. Using private.googleapis.com for other APIs ensures these APIs are accessible over the public internet, aligning with your requirements.
upvoted 1 times
...
hyosung
8 months ago
Selected Answer: B
I think B is correct answer as per following: I doubted that how to connect from on-prem, but, it's described by following on the docs: Direct on-premises traffic to specific IP addresses and regions when accessing Google APIs. https://cloud.google.com/vpc/docs/private-service-connect#google-apis
upvoted 1 times
...
rglearn
8 months, 1 week ago
Selected Answer: B
Option B because Private service connect option can allow us to select specific google services to which we want to connect privately. Option C is also technically correct but question demands rest all API should go over the internet which is not possible in this Options.
upvoted 1 times
...
welkinwalker
10 months, 3 weeks ago
Selected Answer: C
this is the common case for PGA for on-premise
upvoted 2 times
...
pk349
1 year, 2 months ago
• B. Use Private Service Connect ***** to access Cloud Storage, and use the default public domains for all other Google APIs and services. Private Service Connect Private Service Connect allows private consumption of services across VPC networks that belong to different groups, teams, projects, or organizations. You can publish and consume services using IP addresses that you define and that are internal to your VPC network. You can use Private Service Connect to access Google APIs and services, or managed services in another VPC network.
upvoted 1 times
desertlotus1211
9 months, 3 weeks ago
this doesn't address the on-premise access to cloud storage.
upvoted 1 times
gcpengineer
6 months, 3 weeks ago
C doesnt talk abt internet access of other apis
upvoted 2 times
...
...
...
pfilourenco
1 year, 3 months ago
Selected Answer: B
B is correct.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago