GCP-PCNE Google Cloud Professional Cloud Network Engineer Practice Questions
Prepare for GCP-PCNE with more than an answer.
Unlock the full exam and previous versions
- v1Google Cloud Professional Cloud Network Engineer 153 questions Current
- PCNELegacy Professional Cloud Network Engineer 308 questions Locked
- Exam fee
- $200 USD
- Time limit
- 120 minutes
- Questions on the exam
- 50-60
- Passing score
- Pass/Fail (approximately 70%)
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 6
- Designing and Planning a Google Cloud Virtual Private Cloud (VPC) Network24%
- Implementing a VPC Network19%
- Configuring Managed Network Services16%
- Configuring and Implementing Hybrid and Multi-Cloud Network Interconnectivity15%
- Managing, Monitoring, and Troubleshooting Network Operations12%
- Configuring, Implementing and Managing a Cloud Network Security Solution14%
- 1
You are designing a solution to expose a service running in a VPC to another consumer VPC in the same organization without using VPC Peering or external IP addresses. The consumer VPCs might have overlapping IP ranges with the producer VPC. Which service should you choose?
Show answer details
Correct answer: C
Private Service Connect (PSC) allows you to expose services to consumers using a local IP in the consumer's VPC. It works even if the VPCs have overlapping IP ranges because it uses a specific endpoint model rather than merging routing tables like Peering does.
- 2
You need to configure a load balancer for a global application that serves TCP traffic on a non-standard port (not 80/443). The application requires the client IP address to be preserved. Which load balancer type is appropriate?
Show answer details
Correct answer: B
The Global External Proxy Network Load Balancer (formerly SSL Proxy or TCP Proxy) supports TCP traffic on various ports and can terminate SSL. However, for preserving client IP, the Proxy protocol must be enabled or header insertion used. Wait, 'External Passthrough Network Load Balancer' preserves IP natively but is Regional. The question asks for 'Global'. The External TCP/SSL Proxy LB is global. To preserve Client IP in Proxy LB, you enable PROXY protocol. This is the best fit for 'Global' + 'Non-standard TCP'.
- 3
You are migrating a legacy application to Google Cloud that uses hardcoded IPv6 addresses. You need to create a Dual-Stack VPC. Which constraint must you consider when designing the subnets?
Show answer details
Correct answer: C
In Google Cloud, when you enable IPv6 on a dual-stack subnet, the IPv6 CIDR range is always fixed at /64. You cannot choose a different size.
- 4
You are creating a Case Study for a global logistics company. They have 50 branch offices connecting to Google Cloud via VPN. They want to use Network Connectivity Center (NCC) to allow branch-to-branch communication through the Google Cloud backbone. What specific NCC feature must be enabled to allow this traffic flow?
Show answer details
Correct answer: B
To allow data to flow between spokes (like VPN spokes connected to branch offices) through the NCC hub, you must explicitly enable 'site-to-site data transfer'. This feature allows traffic to transit the Google global network between on-premises locations.
- 5
You are the Lead Network Architect for a global retail company. You are designing a network architecture for a new e-commerce platform that requires 99.99% availability for hybrid connectivity between your on-premises data center and Google Cloud. The application is sensitive to latency and requires high bandwidth (approx 20 Gbps). You need to select the connectivity solution that meets the SLA and bandwidth requirements while minimizing latency. Which architecture should you choose?
Show answer details
Correct answer: B
To achieve the 99.99% SLA for Dedicated Interconnect, Google Cloud requires four connections: two in one metropolitan area (in different edge availability domains) and two in a second metropolitan area (in different edge availability domains). This ensures resilience against both single-device failures and entire metro-level failures. A single metro setup only provides a 99.9% SLA.
- 6
A multinational corporation is deploying a Shared VPC topology. They have a host project containing the Shared VPC and multiple service projects for different departments (HR, Finance, Engineering). The Engineering department needs to deploy a Google Kubernetes Engine (GKE) cluster in their service project using the shared network. Which specific IAM roles must be granted to the GKE service account in the host project to allow the GKE cluster to manage networking resources correctly?
Show answer details
Correct answer: C
For a GKE cluster in a service project to use a Shared VPC, the GKE service account (service-[PROJECT_NUMBER]@container-engine-robot.iam.gserviceaccount.com) from the service project needs the 'Kubernetes Engine Host Service Agent User' role on the host project. Additionally, the 'Compute Network User' role is typically required for the Google APIs service agent to manage network resources like firewalls and routes.
