Managing, monitoring, and troubleshooting network operations
Drill 19 practice questions focused entirely on Managing, monitoring, and troubleshooting network operations for the Google Cloud PCNE exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
You operate a production VPC connected to on-premises via HA VPN. Last week a tunnel went down for 40 minutes before anyone noticed, causing an outage. The network team wants to be paged immediately whenever any VPN tunnel loses its BGP session or drops. Using Google Cloud Observability, what is the most appropriate way to implement this proactive notification?
A fleet of 200 instances in a private subnet uses a single Cloud NAT gateway to reach an external payment API. During peak traffic, application logs show many outbound connections to the same API endpoint failing intermittently. Cloud Monitoring shows the 'dropped_sent_packets' metric for the NAT gateway spiking, while CPU and bandwidth on the instances remain low. What is the most likely cause and the correct remediation?
A workload on VM-A (subnet 10.0.1.0/24) cannot reach an internal passthrough Network Load Balancer VIP in another VPC connected via VPC peering. You run a Connectivity Test from VM-A to the VIP, and the test reports 'Reachable' for the forward path. However, actual application traffic still times out. You suspect an asymmetric routing or return-path problem. Which action within Network Intelligence Center best confirms the return-path issue?
A network engineer at a retail company reports that VMs in a Google Cloud VPC cannot reach an on-premises subnet (10.50.0.0/24) that is connected via HA VPN and a Cloud Router using BGP. Traffic in the reverse direction (on-prem to Google Cloud) works fine. The engineer runs a Connectivity Test from a VM in the VPC to a host at 10.50.0.5, and the test result reports 'Route not found: no matching route for the destination' at the VPC network step. What is the most likely root cause?
A developer reports that a VM named app-vm in subnet 10.10.0.0/24 cannot reach a database VM named db-vm on TCP port 5432 in subnet 10.20.0.0/24 within the same VPC. Both VMs are running and have correct IP configurations. You want to quickly determine, without generating live traffic, whether a firewall rule is blocking the connection and identify exactly which rule is responsible. What should you do?
A network engineer runs a Connectivity Test between a Compute Engine VM and an on-premises host reachable over HA VPN. The test result reports 'Reachable' based on configuration analysis, but users still report that actual traffic is failing intermittently. The engineer needs the test to also verify whether packets are truly being delivered across the live data plane, not just that the configuration permits the flow. What should the engineer do?
A security engineer at your company runs a monthly review of firewall posture across a production VPC. She wants Google Cloud to automatically surface allow rules that permit a much broader IP range or port set than the traffic actually observed hitting those rules, so she can tighten them. Which Network Intelligence Center capability should she use to obtain these specific findings?
A security team at your company complains that a legacy firewall rule allowing SSH (tcp:22) from a broad source range appears to never take effect, and they suspect it is being overridden by a higher-priority rule. They also want to identify rules that have received zero hits over the past several weeks so they can safely remove them. Which Network Intelligence Center capability should you use to provide both the override analysis and the usage data?
A security engineer reports that traffic from a partner subnet (192.168.50.0/24) to a set of internal application VMs is being unexpectedly denied. You suspect a specific egress or ingress firewall rule is responsible, but you cannot confirm which rule is matching the denied packets. You need to see, per-connection, exactly which firewall rule is evaluating this traffic and whether it is allowing or denying it, with minimal changes to the environment. What should you do?
A company runs an application on Compute Engine VMs in a VPC configured with an MTU of 1460. The VMs communicate with an on-premises data center over an HA VPN tunnel. Users report that small requests succeed, but large file transfers and certain database queries hang or time out intermittently. Ping with default packet sizes works fine between the VMs and on-premises hosts. What is the MOST likely cause and the correct action to resolve it?
Your organization runs workloads across three projects that share a common Shared VPC. Application owners report intermittent latency between a frontend service in one project and a backend service in another. Before opening a support case, you want to visually confirm the actual traffic paths, identify which regions the traffic traverses, and see aggregated throughput and packet-loss indicators between the VM instances involved — using observed telemetry rather than a synthetic simulation. Which Network Intelligence Center capability should you use?
A retail company runs a fleet of VMs in us-central1 and europe-west1. The finance team flags a sudden spike in inter-region egress charges last month. As the network engineer, you need to quickly identify which specific workloads and traffic flows are driving the cross-region data transfer so you can recommend architectural changes. Which Network Intelligence Center capability provides the fastest way to visualize these traffic flows and their associated volumes across regions?
Your finance team flags an unexpected spike in inter-region and internet egress charges. You need to visually identify which specific VM instances and services are generating the highest volume of cross-region and external traffic over the past several weeks, along with the associated throughput and packet-loss metrics for each traffic flow. Which Network Intelligence Center capability should you use?
Your operations team reports that a monitoring application running on Compute Engine instances in us-central1 is intermittently sending large volumes of traffic to an external endpoint, but nobody can identify which VMs are responsible or the volume of bytes involved. You need a tool that provides an interactive, graphical view showing the entities in your network, the traffic flows between them, and associated throughput and latency metrics aggregated over time — without deploying any agents. Which Network Intelligence Center capability should you use?
Users of a latency-sensitive application hosted on Compute Engine instances in us-central1 report intermittent slowness when connecting from clients in europe-west1. Your team is unsure whether the degradation is caused by the Google backbone, by their own VPC configuration, or by something on the client side. Before opening a support case, you want to determine whether packet loss and latency between the two regions are elevated across Google's network generally, or only for traffic within your specific project. Which Network Intelligence Center feature and view should you use?
Your company runs latency-sensitive workloads across two Google Cloud regions in the same project. Application teams report intermittent slowness, and you need to determine whether the problem is caused by packet loss or increased latency on the underlying Google network (not the application or your own VPC configuration). You want to compare current inter-region and inter-zone performance against a historical baseline without deploying any agents or probes. Which Network Intelligence Center tool should you use?
Your security team wants to analyze traffic between two specific subnets in a production VPC without incurring the full cost of logging every flow. They need the exported logs to include the destination Google service name and the geographic region of external endpoints so they can build BigQuery reports. VPC Flow Logs are currently enabled with default settings on the relevant subnet. What is the most cost-effective way to meet these requirements?
Your security team enabled VPC Flow Logs on a busy subnet hosting thousands of high-throughput VMs. Cloud Logging costs have risen sharply, but the team still needs enough traffic visibility to investigate occasional connection anomalies. They do not require every packet flow to be captured. What is the most effective way to reduce logging costs while retaining useful diagnostic data?
An application team reports intermittent connection resets between two VM tiers in the same subnet. You suspect asymmetric traffic or dropped flows, but the existing VPC Flow Logs configuration on the subnet uses a 0.5 (50%) sampling rate with a 5-second aggregation interval and default metadata. You need to capture the most complete, granular record of individual flows during a scheduled 30-minute reproduction window while minimizing changes elsewhere. What should you do?
More PCNE practice
Keep going with the other Google Cloud Professional Cloud Network Engineer domains, or take a full timed mock exam.
← Back to PCNE overview