GCP-PCNE Sample Questions & Answers
Designing an overall VPC network architecture carries the biggest weight, alongside configuring routing and connectivity, load balancers, Cloud CDN, and Cloud DNS, then hybrid links through Cloud Interconnect, observability, and Cloud Armor or NGFW policies.
Launch the full GCP-PCNE simulator →Showing 6 of 12 free samples.
- Question 1Intermediate
Designing and Planning a Google Cloud VPC Network · Designing a resilient and performant hybrid and multi-cloud network
You are consulting for a company that needs to connect their on-premises network to Google Cloud. They require private access to Google APIs (like Cloud Storage and BigQuery) from their on-premises hosts without assigning public IP addresses to the on-prem hosts. They have an existing Cloud VPN connection. Which configuration should you implement?
Show answer & explanation
Correct answer: B
Private Google Access for on-premises hosts requires two main steps: 1) Advertising the restricted.googleapis.com (199.36.153.4/30) or private.googleapis.com (199.36.153.8/30) VIPs over the Cloud VPN to on-prem via Cloud Router custom advertisements. 2) Configuring on-premises DNS to resolve Google API domains (CNAME) to these specific VIPs. Simply enabling PGA on the subnet only helps VM instances in that subnet, not on-prem hosts.
- Question 2Beginner
Designing and Planning a Google Cloud VPC Network · Designing VPC networks
You are designing a multi-region VPC network. You want to ensure that if a regional failure occurs, traffic can be automatically rerouted to a standby region via your Cloud VPN connections. You are using Cloud Router for dynamic routing. What routing mode must you select for the VPC network to support this failover scenario?
Show answer & explanation
Correct answer: C
Global dynamic routing allows Cloud Routers to advertise subnets from all regions to on-premises peers and learn routes from on-premises peers available to all regions. This is essential for multi-region failover, as it allows the network to be aware of alternative paths through different regions.
- Question 3Intermediate
Designing and Planning a Google Cloud VPC Network · Designing a resilient and performant hybrid and multi-cloud network
Your organization requires a secure connection between Google Cloud and AWS. You need to establish a high-bandwidth, low-latency connection without traversing the public internet. The solution must support SLA commitments. Which Google Cloud service should you design into your architecture?
Show answer & explanation
Correct answer: C
Cross-Cloud Interconnect is a managed service specifically designed to connect Google Cloud to other cloud providers like AWS, Azure, and Oracle Cloud. It provides high bandwidth (10Gbps or 100Gbps), an SLA, and does not use the public internet, meeting all the requirements.
- Question 4Intermediate
Designing and Planning a Google Cloud VPC Network · Designing a resilient and performant hybrid and multi-cloud network
You are designing a network for a legacy application that requires Layer 2 connectivity between the on-premises network and Google Cloud to support non-IP protocols. Which Google Cloud hybrid connectivity option supports this requirement?
Show answer & explanation
Correct answer: D
Google Cloud VPCs are strictly Layer 3 (IP-based) networks. They do not support Layer 2 connectivity (Ethernet switching, non-IP protocols) natively across Interconnect or VPN. To support legacy Layer 2 apps, you would need an overlay solution (like VXLAN) running on top of the Layer 3 connectivity, or refactor the application.
- Question 5Intermediate
Designing and Planning a Google Cloud VPC Network · Designing VPC networks
A company is using a Hub-and-Spoke topology with VPC Network Peering. The Hub VPC is connected to on-premises via Cloud VPN. The Spoke VPCs are peered with the Hub VPC. Resources in the Spoke VPCs cannot reach the on-premises network. What is the most likely cause?
Show answer & explanation
Correct answer: A
VPC Network Peering is non-transitive. If Spoke A is peered with Hub, and Hub is connected to On-Prem, Spoke A cannot utilize the Hub's connection to reach On-Prem directly through the peering alone. To solve this, you must export custom routes from the Hub (including the dynamic routes from VPN) and import them into the Spoke.
- Question 6Beginner
Designing and Planning a Google Cloud VPC Network · Designing VPC networks
You are designing a solution to expose a service running in a VPC to another consumer VPC in the same organization without using VPC Peering or external IP addresses. The consumer VPCs might have overlapping IP ranges with the producer VPC. Which service should you choose?
Show answer & explanation
Correct answer: D
Private Service Connect (PSC) allows you to expose services to consumers using a local IP in the consumer's VPC. It works even if the VPCs have overlapping IP ranges because it uses a specific endpoint model rather than merging routing tables like Peering does.
Ready for the real thing?
The full GCP-PCNE simulator has every exam-style question, timed mode, and instant scoring.