Google Cloud Professional Cloud Network Engineer · Domain 4 · 16% of exam

Configuring and implementing hybrid and multicloud network interconnectivity

Drill 20 practice questions focused entirely on Configuring and implementing hybrid and multicloud network interconnectivity for the Google Cloud PCNE exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

Your company runs a Classic VPN gateway connecting its on-premises data center to a Google Cloud VPC. The Classic VPN uses static routes and a single tunnel. Leadership now requires a 99.99% availability SLA for this hybrid connection. Which approach correctly migrates the connectivity to meet the SLA requirement?

Reviewed for accuracy · Report an issue
Question 2 of 20

You configured an HA VPN tunnel between Google Cloud and an on-premises router. The tunnel status shows 'Established', but the BGP session on the Cloud Router remains in a state where routes are not being exchanged. You verify that the Cloud Router uses Google ASN 65001 and advertises subnet routes correctly. On the on-premises side, the peer is configured with ASN 65001 as its local ASN, and the BGP peer IP addresses fall within the same /30 link-local range you assigned in the BGP session configuration. What is the most likely cause of the BGP session failure?

Reviewed for accuracy · Report an issue
Question 3 of 20

Your company runs an HA VPN connection between an on-premises data center and a Google Cloud VPC named prod-vpc. The Cloud Router uses BGP to exchange routes. The on-premises router currently learns the subnet ranges in prod-vpc. You have now enabled Private Google Access and want the on-premises hosts to also reach Google APIs through the tunnel using the restricted.googleapis.com range (199.36.153.4/30), which is NOT a subnet in your VPC. What is the correct way to make the on-premises router learn this range via BGP?

Reviewed for accuracy · Report an issue
Question 4 of 20

Your company runs an HA VPN connection between an on-premises data center and a Google Cloud VPC, using a Cloud Router with BGP. During periods of transient network latency on the WAN link, the BGP sessions repeatedly drop and re-establish, causing routes to flap and briefly interrupting traffic. The on-premises router administrator asks what BGP timer setting on the Cloud Router side you can adjust to make the session more tolerant of brief connectivity interruptions before it is declared down. What should you do?

Reviewed for accuracy · Report an issue
Question 5 of 20

Your company runs a Cloud Router with a BGP session to an on-premises router over HA VPN. By default the Cloud Router advertises all subnets in the VPC. The network team now wants the Cloud Router to advertise only a single aggregate prefix (10.100.0.0/16) that summarizes several subnets, plus the range for a Private Google Access endpoint (199.36.153.8/30), while suppressing individual subnet advertisements. What should you configure on the Cloud Router?

Reviewed for accuracy · Report an issue
Question 6 of 20

Your company has two Dedicated Interconnect connections in the same metropolitan area, each terminating on a different Google edge availability domain. You create one VLAN attachment on each connection, both associated with a single Cloud Router in the us-central1 region. Your on-premises router advertises the same on-premises prefix (10.50.0.0/16) over both BGP sessions with identical MED values, and both attachments have the same egress capacity. You want Google Cloud to distribute egress traffic toward on-premises across both VLAN attachments simultaneously. What must be true for Cloud Router to perform this load distribution?

Reviewed for accuracy · Report an issue
Question 7 of 20

Your company has established an HA VPN gateway connecting a Google Cloud VPC to an on-premises data center. Two tunnels are up, each with its own BGP session on the same Cloud Router, and both peers advertise the identical on-premises prefix 10.50.0.0/16 with the same MED value. You want traffic from the VPC toward the on-premises network to be distributed across both tunnels simultaneously to maximize aggregate throughput. What must be true for the Cloud Router to program equal-cost multi-path (ECMP) routes across both tunnels?

Reviewed for accuracy · Report an issue
Question 8 of 20

Your company has provisioned a single 10-Gbps Dedicated Interconnect connection at a Google colocation facility. Traffic to Google Cloud has grown, and the network team wants to increase capacity to 20 Gbps on the same connection while keeping a single logical link between your on-premises router and Google's edge. What is the correct way to achieve this?

Reviewed for accuracy · Report an issue
Question 9 of 20

Your company has provisioned a single 10 Gbps Dedicated Interconnect connection in a colocation facility. You need to create a VLAN attachment that will carry production traffic to a VPC in us-central1. The finance team requires that you only pay for the capacity you actually configure on the attachment, and the application is expected to peak at around 5 Gbps. Which action correctly configures the VLAN attachment for this requirement?

Reviewed for accuracy · Report an issue
Question 10 of 20

Your company has provisioned a 10 Gbps Dedicated Interconnect connection and created a VLAN attachment linking your on-premises router to a Cloud Router in a custom-mode VPC. Applications transferring large datasets between on-premises hosts and Compute Engine VMs are experiencing fragmentation and lower-than-expected throughput. You want the traffic across the Interconnect to use 8896-byte jumbo frames end to end. What must you configure to achieve this?

Reviewed for accuracy · Report an issue
Question 11 of 20

Your company has provisioned a 10 Gbps Dedicated Interconnect connection terminating at a colocation facility. Your production VPC has resources in the us-central1 region, and you need to create a VLAN attachment so that on-premises traffic can reach those resources. When you create the VLAN attachment, the Cloud Router it associates with must be in a specific region. To minimize latency and egress cost for traffic between on-premises and your us-central1 workloads, in which region should you create the VLAN attachment and its Cloud Router?

Reviewed for accuracy · Report an issue
Question 12 of 20

You are deploying an HA VPN gateway in a Google Cloud project to connect to your on-premises data center. You have configured the HA VPN gateway with two interfaces and created two tunnels to two separate on-premises VPN peer devices. You now need to establish dynamic routing between Google Cloud and on-premises. Which action correctly establishes the BGP sessions for this HA VPN configuration?

Reviewed for accuracy · Report an issue
Question 13 of 20

Your company has deployed an HA VPN gateway in the us-central1 region connecting to a single on-premises peer device that supports BGP. You created one HA VPN gateway (two interfaces), two tunnels, and attached them to a single Cloud Router. Both BGP sessions are established and both tunnels are UP. However, you notice that traffic from Google Cloud to on-premises only uses one tunnel at a time; the second tunnel carries no egress traffic under normal conditions. You want Google Cloud to actively load-share egress traffic across both tunnels. What should you configure?

Reviewed for accuracy · Report an issue
Question 14 of 20

Your company runs an HA VPN connection between an on-premises data center and a Google Cloud VPC. The Cloud Router uses the default (base) advertisement mode and currently advertises only the subnets in the local VPC over BGP. You recently configured Private Google Access and now need the on-premises hosts to reach Google APIs through the VPN using the restricted VIP range (199.36.153.4/30), which is NOT a subnet in the VPC. What is the correct way to make the Cloud Router advertise this range to the on-premises peer?

Reviewed for accuracy · Report an issue
Question 15 of 20

You configured an HA VPN gateway in Google Cloud with two tunnels to your on-premises router. The BGP sessions on Cloud Router remain in a non-established state, and the tunnel status shows 'First handshake' and never reaches 'Established'. You confirmed the on-premises firewall allows UDP 500 and UDP 4500, and the peer IP addresses are correct. What is the MOST likely cause and the correct action to take?

Reviewed for accuracy · Report an issue
Question 16 of 20

Your company needs hybrid connectivity to a single Google Cloud region. The finance team approved a budget that allows only a single Partner Interconnect connection tier, but the operations team requires a documented 99.9% availability SLA for the VLAN attachment. During design review, an engineer proposes placing a single VLAN attachment on one edge availability domain. What must you change to actually qualify for the 99.9% SLA on Partner Interconnect?

Reviewed for accuracy · Report an issue
Question 17 of 20

Your company runs production workloads in a single Google Cloud VPC and requires connectivity to two separate on-premises data centers, each with its own peer VPN gateway. Management requires the 99.99% availability SLA for the HA VPN connection to each data center. You are designing the HA VPN gateway configuration. How should you configure the HA VPN gateway and tunnels to meet the 99.99% SLA for connectivity to each data center?

Reviewed for accuracy · Report an issue
Question 18 of 20

Your company is setting up a Partner Interconnect connection through a supported service provider. You have created the VLAN attachment in your Google Cloud project and now need to complete provisioning with the partner. Which value must you provide to the service provider so they can establish the connection to your VLAN attachment, and what happens after they configure their side?

Reviewed for accuracy · Report an issue
Question 19 of 20

Your company is provisioning a Partner Interconnect connection through a service provider. You have created a VLAN attachment (which generated a pairing key) and shared the pairing key with the provider, but the attachment remains in a PENDING_PARTNER state and BGP never establishes. What is the correct sequence of responsibilities to bring the connection to an operational state?

Reviewed for accuracy · Report an issue
Question 20 of 20

Your company has ordered a Partner Interconnect connection through a supported service provider. In the Google Cloud console you have created a VLAN attachment and received a pairing key, which you provided to your provider. The provider reports they have configured their side, but the VLAN attachment still shows an inactive state and you cannot pass traffic. What is the required next step to bring the attachment into service?

Reviewed for accuracy · Report an issue

More PCNE practice

Keep going with the other Google Cloud Professional Cloud Network Engineer domains, or take a full timed mock exam.

← Back to PCNE overview