exam questions

Exam Professional Cloud Network Engineer All Questions

View all questions & answers for the Professional Cloud Network Engineer exam

Exam Professional Cloud Network Engineer topic 1 question 89 discussion

Actual exam question from Google's Professional Cloud Network Engineer
Question #: 89
Topic #: 1
[All Professional Cloud Network Engineer Questions]

You are the network administrator responsible for hybrid connectivity at your organization. Your developer team wants to use Cloud SQL in the us-west1 region in your Shared VPC. You configured a Dedicated Interconnect connection and a Cloud Router in us-west1, and the connectivity between your Shared VPC and on-premises data center is working as expected. You just created the private services access connection required for Cloud SQL using the reserved IP address range and default settings. However, your developers cannot access the Cloud SQL instance from on-premises. You want to resolve the issue. What should you do?

  • A. 1. Modify the VPC Network Peering connection used for Cloud SQL, and enable the import and export of routes.
    2. Create a custom route advertisement in your Cloud Router to advertise the Cloud SQL IP address range.
  • B. 1. Change the VPC routing mode to global.
    2. Create a custom route advertisement in your Cloud Router to advertise the Cloud SQL IP address range.
  • C. 1. Create an additional Cloud Router in us-west2.
    2. Create a new Border Gateway Protocol (BGP) peering connection to your on-premises data center.
    3. Modify the VPC Network Peering connection used for Cloud SQL, and enable the import and export of routes.
  • D. 1. Change the VPC routing mode to global.
    2. Modify the VPC Network Peering connection used for Cloud SQL, and enable the import and export of routes.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ccieman2016
Highly Voted 1 year, 8 months ago
Selected Answer: A
B and D is wrong, VPC routing mode global is default, not necessary to changed. C is wrong, no make sense additional cloud router. in my opinion, Letter A is sure.
upvoted 8 times
aygitci
7 months ago
Not sure that VPC routing mode is global ...
upvoted 1 times
...
desertlotus1211
5 months, 2 weeks ago
how do you figure VPC peering is needed?
upvoted 1 times
desertlotus1211
5 months, 2 weeks ago
nevermind I researched Private service connection. Indeed it mentions VPC peering don automatically for GCP services in producer VPC
upvoted 1 times
...
...
...
Kyle1776
Most Recent 8 months ago
Selected Answer: B
Can someone explain to me where this question mentions VPC peering or more than one VPC for that matter? "You are the network administrator responsible for hybrid connectivity at your organization. Your developer team wants to use Cloud SQL in the us-west1 region in your Shared VPC. You configured a Dedicated Interconnect connection and a Cloud Router in us-west1, and the connectivity between your Shared VPC and on-premises data center is working as expected. You just created the private services access connection required for Cloud SQL using the reserved IP address range and default settings. However, your developers cannot access the Cloud SQL instance from on-premises. You want to resolve the issue. What should you do?" Going with B.
upvoted 2 times
Aenarion
1 week ago
When you create a Private Services Access connection, it establishes VPC Peering between your Shared VPC and the Google-managed services VPC (where Cloud SQL resides). By default, VPC Peering does NOT exchange routes automatically.
upvoted 1 times
...
...
gcpengineer
11 months, 1 week ago
Selected Answer: B
#B is the ans
upvoted 2 times
...
i_0_i
11 months, 3 weeks ago
A is correct. This question is about "Private services access and on-premises connectivity". See this link, https://cloud.google.com/vpc/docs/private-services-access#on-premises-connectivity By default, on-premises hosts can't reach the service producer's network by using private services access. In the VPC network, you might have custom static or dynamic routes to correctly direct traffic to your on-premises network. However, the service producer's network doesn't contain those same routes. When you create a private connection, the VPC network and service producer network exchange subnet routes only. You must export the VPC network's custom routes so that the service provider's network can import them and correctly route traffic to your on-premises network. Update the VPC peering configuration associated with the private connection to export custom routes. Then, https://cloud.google.com/vpc/docs/using-vpc-peering#update-peer-connection Updating a peering connection can import and export custom routes.
upvoted 4 times
...
Laryoul
1 year, 2 months ago
Selected Answer: B
A and D is wrong for me. With private services access the connection between consumer and producer uses VPC Network Peering.Because the connection between the consumer and the producer is made using VPC Network Peering, you don’t need to import and export routes. Subnet routes that don't use privately used public IP addresses are always exchanged between peered VPC networks. I go throught B because when I create VPC the default routing mode is Regional. Don't you ?
upvoted 3 times
...
Goram113
1 year, 6 months ago
Selected Answer: A
A Here is very similar case: https://cloud.google.com/database-migration/docs/mysql/configure-connectivity-vpns#dynamic-routes
upvoted 2 times
...
pk349
1 year, 6 months ago
• A. 1. Modify the VPC Network ***** Peering connection used for Cloud SQL, and enable the import and export of routes. 2. Create a custom route ***** advertisement in your Cloud Router to advertise the Cloud SQL IP address range.
upvoted 2 times
...
AzureDP900
1 year, 7 months ago
A is right https://cloud.google.com/network-connectivity/docs/router/concepts/overview#route-advertisement
upvoted 1 times
...
mshry
1 year, 7 months ago
In my opinion you do not have any control over the VPC peering for PSA. You will need to do a custom advert though, from your VPC onwards to on-premises.
upvoted 1 times
...
pfilourenco
1 year, 8 months ago
Selected Answer: A
A is the correct.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago