Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Professional Cloud Network Engineer Exam - Topic 4 Question 127 Discussion

Your company acquired a new division. The new division's network team requires complete control over their networking infrastructure. You need to extend your existing Google Cloud network infrastructure, that consists of a single VPC, to allow workloads from all divisions to communicate with each other. You want to avoid incurring extra costs and granting unnecessary permissions to the new division's networking team. What should you do?
A) Q * Create a new project for the new division's network team. * Create a new VPC within the new project. * Establish a VPC peering between your existing VPC and the new division's VPC. * Grant roles/compute. networkAdmin on the newly created project to the new division's network team group.
B) O * Create a new project for the new division's network team. * Create a new VPC within the new project. * Establish a VPC peering between your existing VPC and the new division's VPC. * Create a new subnet dedicated to the new division's workloads. * Grant roles/compute .networkuser on the new project to the new division's network team group.
C) O * Create a new project for the new division's network team. * Create a new VPC within the new project. * Establish a VPN connection between your existing VPC and the new division's VPC. * Grant roles/compute .networkAdmin on the newly created project to the new division's network team group.
D) Q * Ensure that the project hosting the existing network infrastructure is enabled as a host project. * Create a new subnet dedicated to the new division's workloads in the existing VPC. * Grant roles/compute. networkuser on the newly created subnet to the new division's network team group.

Google Professional Cloud Network Engineer Exam - Topic 4 Question 127 Discussion

Actual exam question for Google's Professional Cloud Network Engineer exam
Question #: 127
Topic #: 4
[All Professional Cloud Network Engineer Questions]

Your company acquired a new division. The new division's network team requires complete control over their networking infrastructure. You need to extend your existing Google Cloud network infrastructure, that consists of a single VPC, to allow workloads from all divisions to communicate with each other. You want to avoid incurring extra costs and granting unnecessary permissions to the new division's networking team. What should you do?

Show Suggested Answer Hide Answer
Suggested Answer: A

The requirement for the new division's network team to have 'complete control over their networking infrastructure' while allowing communication between divisions and avoiding unnecessary permissions points directly to VPC Network Peering. This approach allows each division to manage its own VPC independently (in its own project), provides full control to the new division's network team within their project, and enables secure, private communication between the VPCs without traversing the public internet. Granting roles/compute.networkAdmin on their newly created project ensures they have the necessary control over their dedicated VPC. Using Shared VPC (option D) would centralize network administration under your existing project, which goes against the requirement of the new division having 'complete control.' VPN (option C) would incur additional costs and introduce more complexity than VPC peering for intra-Google Cloud connectivity. Option B is flawed because creating a subnet in the new VPC isn't directly relevant to granting permissions on the new project for VPC peering setup, and networkuser role on the new project alone wouldn't give complete network control.

Exact Extract:

'VPC Network Peering allows you to connect two VPC networks so that resources in each network can communicate with each other using internal IP addresses. Traffic stays within Google's network.'

'Each side of a VPC Network Peering connection is configured independently. This means that each network administrator retains full control over their own network, including routes, firewalls, and network services.'


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel