โ† All Cloud Engineer Flashcard Decks

Cloud Engineer Networking & Connectivity Flashcards

6 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Cloud Engineer Networking & Connectivity flashcards as text
  1. A GCP VM needs to communicate privately with a Google managed service (like Cloud Storage) without sending traffic over the internet. What feature enables this?

    Answer: Private Google Access

    Private Google Access allows VMs with only internal IP addresses to reach Google APIs and services over Google's internal network without needing an external IP.

  2. Which GCP feature provides DDoS protection and is automatically included with the global HTTP(S) Load Balancer?

    Answer: Cloud Armor

    Cloud Armor provides DDoS protection and WAF capabilities and integrates directly with the global HTTP(S) Load Balancer as its security policy engine.

  3. What is the minimum number of Cloud VPN tunnels needed to achieve 99.99% availability for a VPN connection to on-premises?

    Answer: 4

    HA VPN with 99.99% SLA requires two HA VPN gateways each with two interfaces, creating 4 tunnels total across two on-premises peer gateways for full redundancy.

  4. Which Cloud DNS record type is used to map a hostname to an IPv6 address?

    Answer: AAAA record

    AAAA records map a domain name to an IPv6 address, while A records map to IPv4 addresses.

  5. You want to send all internet-bound traffic from a subnet through a centralized firewall VM. What GCP feature enables this custom routing?

    Answer: Custom static routes with a next-hop VM

    Creating a custom static route with a next-hop pointing to a VM instance (firewall appliance) forces traffic matching the destination to traverse that VM.

  6. What is the purpose of Alias IP ranges on a GCP VM instance?

    Answer: Assign multiple internal IP addresses or ranges to a single VM interface

    Alias IP ranges allow a single VM network interface to have additional internal IP addresses or subnets, useful for containers or multiple services running on one VM.