🔥 3-day streak
Google Cloud Professional Cloud Network Engineer129 / 142
Question 129 of 142

A large enterprise runs a central networking team that must own all VPC networks, subnets, and firewall rules. Twelve application teams each operate in their own Google Cloud project and deploy Compute Engine and GKE workloads that all need private connectivity to a common on-premises data center over existing HA VPN tunnels. The networking team wants to avoid managing peering meshes and wants to centrally control routing and firewalls while letting app teams retain autonomy over their own resources and IAM. Which design best meets these requirements?

Reviewed for accuracy · Report an issueNext question