Skip to content

Implementing a VPC network Questions

Practice questions for Implementing a VPC network topic in Google Professional Cloud Network Engineer. 36 questions covering this domain.

36 questions10 easy19 medium7 hard
Q1
hard

You increase the MTU of a VPC network from 1460 to 1500. Existing Linux and Windows VMs must start using the new MTU. Which action is required?

Q2
medium

Two ingress firewall rules match the same traffic. One rule allows TCP 80 at priority 900, and the other denies all traffic at priority 1000. What is ...

Q3
medium

You are creating an ingress firewall rule and want to define targets and sources. Which combination is invalid in a single firewall rule?

Q4
easy

A new VPC firewall rule does not specify a priority. What priority does Google Cloud assign by default?

Q5
easy

Which target selector is generally the stricter choice for VPC firewall rules when you want tight control over which VMs a rule applies to?

Q6
easy

A subnet contains VM instances that have only internal IP addresses and need to reach Google APIs and services. Which subnet-level setting must you en...

Q7
medium

A security team creates a VPC firewall rule in VPC A and expects it to apply to instances in peered VPC B. What actually happens?

Q8
medium

A VM is allowed to open an outbound TCP connection by an egress firewall rule. Which statement about the return traffic is correct?

Q9
medium

An engineer worries that a restrictive firewall rule could lock down access to the metadata server at 169.254.169.254. What is the correct expectation...

Q10
hard

A network engineer wants to use VPC Network Peering to exchange policy-based routes between two VPC networks. What should you tell them?

Q11
hard

A company runs a third-party firewall appliance as a VM in Google Cloud. To ensure all traffic between two internal subnets passes through the applian...

Q12
easy

Which component of a hierarchical firewall policy determines its application scope relative to a VPC firewall rule?

Q13
medium

An organization uses hierarchical firewall policies at the folder level and also has VPC firewall rules in the project. In which order are these evalu...

Q14
easy

A security engineer wants to log all firewall rule matches for a specific ingress allow rule to analyze traffic patterns. Which feature must they enab...

Q15
medium

A team deploys a multi-NIC VM with one NIC in VPC A and one NIC in VPC B. Which routing behavior applies to this VM?

Q16
medium

A VM inside a VPC has a network tag `backend`. An ingress firewall rule allows TCP 8080 from source tag `frontend`. A second ingress firewall rule at ...

Q17
medium

A network team wants to prevent any VM in a project from having an external ephemeral or static IP address assigned. Which mechanism enforces this at ...

Q18
hard

A security team discovers that a developer-tagged VM can reach a database-tagged VM on port 5432, even though no explicit allow rule exists for this c...

Q19
easy

A subnet is created in us-central1 with the default settings. Which IP range is reserved by Google Cloud within every subnet, regardless of size?

Q20
easy

In GKE, what is required to use VPC-native clusters so that Pod IP addresses are routable within the VPC?

Sign in to see all 36 questions

Create a free account to browse all questions — completely free during our launch phase.