Google Cloud
Google Cloud Certified – Professional Cloud Network Engineer
PR000240
Become a certified Professional Cloud Network Engineer with exam code PR000240 to validate your networking skills in Google Cloud.
492 questions
0 views
Free
Questions 131–140 of 492
A company needs to restrict access to a VM instance for specific users. What should they use?
-
A
Network Tags
-
B
Service Accounts
-
C
Firewall Rules
-
D
IAM Roles
Explanation
IAM Roles manage who has access to resources, whereas network tags and firewall rules control traffic instead of user permissions.
You are configuring a Cloud SQL instance. What happens if you set the maintenance window to Sundays at 2 AM?
-
A
Automatic backups occur at that time
-
B
The instance will restart every Sunday
-
C
Maintenance always runs at that time
-
D
No maintenance will occur that day
Explanation
A maintenance window specifies when updates are applied, while the other options inaccurately describe the function of the window.
Which service would you use for implementing VPC peering?
-
A
Cloud Router
-
B
VPC Network
-
C
Cloud Load Balancing
-
D
Cloud Pub/Sub
Explanation
VPC Network is specifically designed for VPC peering; others don't facilitate this directly.
A company needs to ensure traffic routes based on user location. What should they implement?
-
A
Global Load Balancer
-
B
Regional DNS
-
C
Subnetwork ACLs
-
D
Cloud Interconnect
Explanation
Global Load Balancer directs traffic efficiently based on user location; the others don’t provide the same capability.
You are configuring a Cloud Firewall rule; what happens if 'ingress' is selected?
-
A
Blocks outbound traffic
-
B
Allows incoming traffic
-
C
Disables all traffic
-
D
Logs only malicious traffic
Explanation
Selecting 'ingress' allows you to manage incoming traffic, whereas the others misinterpret firewall functionalities.
Which service provides private connectivity to Google Cloud?
-
A
Cloud Interconnect
-
B
Cloud Storage
-
C
Cloud Functions
-
D
Cloud Run
Explanation
Cloud Interconnect facilitates dedicated connections.
A company needs to load balance traffic across multiple regions. Which service should they use?
-
A
Global Load Balancing
-
B
Internal Load Balancer
-
C
TCP Proxy Load Balancer
-
D
Regional Backends
Explanation
Global Load Balancing is designed for multi-region traffic.
What happens when you enable VPC flow logs?
-
A
Logs are stored in GCS automatically
-
B
Traffic is encrypted in transit
-
C
You can view logs in Cloud Audit
-
D
Traffic routing is affected
Explanation
Enabling VPC flow logs automatically stores them in GCS.
Which service allows interconnecting on-premises to Google Cloud?
-
A
Cloud VPN
-
B
Cloud Storage
-
C
Cloud SQL
-
D
Cloud Functions
Explanation
Cloud VPN enables secure on-premises connectivity; others serve different functions.
A company needs to ensure higher availability for its applications in two regions. What should they use?
-
A
Cloud CDN
-
B
Cloud Load Balancing
-
C
BigQuery
-
D
Cloud Run
Explanation
Cloud Load Balancing distributes traffic across regions; others don’t offer high availability for apps.