{"id":20123,"date":"2026-09-23T10:58:00","date_gmt":"2026-09-23T10:58:00","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20123"},"modified":"2026-09-23T10:58:00","modified_gmt":"2026-09-23T10:58:00","slug":"google-professional-cloud-network-engineer-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/google-professional-cloud-network-engineer-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Google Professional Cloud Network Engineer Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/professional-cloud-network-engineer-exam-dumps\"><b>Google Professional Cloud Network Engineer Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>Which Google Cloud resource provides an internal IP address for a regional subnet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Subnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN tunnel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A subnet provides an IP address range within a VPC network and is associated with a specific Google Cloud region. VM network interfaces can receive internal addresses from the subnet&#8217;s configured range. Subnets are therefore fundamental to organizing address space for workloads deployed across different regions. A route policy influences traffic forwarding behavior, a VPN tunnel provides encrypted connectivity, and a DNS zone manages name resolution. The subnet itself does not perform routing or DNS functions; instead, it supplies the regional address space from which supported resources can obtain internal IP addresses.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>Which feature lets an organization apply security rules at the folder level?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hierarchical firewall policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service attachment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hierarchical firewall policies allow organizations to define firewall controls at higher levels of the Google Cloud resource hierarchy, including folders and organizations. This makes them useful for centrally enforcing security requirements across multiple projects. Policies established higher in the hierarchy can provide consistent controls that individual project configurations must respect. Cloud NAT performs network address translation, Cloud CDN handles content caching, and a service attachment is associated with Private Service Connect service publishing. Hierarchical firewall policies are therefore appropriate when firewall governance needs to extend beyond an individual project.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>Which connectivity service uses encrypted tunnels across an underlying IP network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dedicated Interconnect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Partner Interconnect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN attachment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud VPN establishes encrypted tunnels between Google Cloud and external networks over an underlying IP network. It is commonly selected when secure hybrid connectivity is needed without requiring a dedicated physical circuit. HA VPN can provide resilient configurations using multiple tunnels and dynamic routing through Cloud Router. Dedicated Interconnect and Partner Interconnect provide private connectivity through Interconnect infrastructure rather than functioning as VPN tunnels. A VLAN attachment is a logical configuration associated with Interconnect connectivity. Therefore, Cloud VPN is the service specifically designed for encrypted tunnel-based connectivity.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>What does a VPC route primarily determine?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS ownership<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall logging destination<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backend health status<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet forwarding destination<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VPC route determines how packets destined for a particular IP range should be forwarded. Routes contain destination information and identify an appropriate next hop or forwarding behavior. Google Cloud uses the available routes to determine how traffic should travel toward its destination. DNS ownership concerns name-resolution administration, firewall logging concerns security-event records, and backend health status determines whether load-balancer backends are eligible to receive traffic. Routes therefore form an important part of the VPC forwarding system by determining the network path packets should follow.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>Which service can translate private source addresses for outbound internet connections?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Router<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Armor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud NAT provides network address translation for supported resources that need outbound connectivity without requiring individual external IP addresses. It can translate internal source addresses into configured NAT addresses when traffic leaves the VPC toward supported destinations. This design allows workloads to remain without directly assigned external addresses while still supporting necessary outbound communication. Cloud Router manages dynamic route exchange, Cloud Armor provides security controls for supported applications, and Cloud DNS manages DNS resolution. Cloud NAT therefore addresses outbound address translation rather than routing control, application protection, or domain-name resolution.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>Which Google Cloud service provides managed caching closer to end users?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Interconnect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Router<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud CDN caches eligible content at Google&#8217;s edge locations, helping serve frequently requested content closer to users. This can reduce latency and decrease the amount of traffic that must travel back to the origin. Cloud CDN is commonly used with supported Google Cloud load-balancing architectures to accelerate delivery of web content and other cacheable resources. Cloud Interconnect provides private network connectivity, Cloud Router exchanges routes using BGP, and Cloud DNS manages DNS services. Cloud CDN therefore addresses content-delivery performance rather than private connectivity, dynamic routing, or name resolution.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>Which configuration enables VPC resources to resolve names hosted by external DNS servers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS forwarding policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall logging rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load-balancer certificate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud NAT gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A DNS forwarding policy can direct DNS queries for specified namespaces toward designated DNS servers. This is useful when workloads in Google Cloud need to resolve names maintained by on-premises infrastructure or another external DNS environment. Forwarding can help create consistent name-resolution behavior across hybrid architectures without requiring every external record to be duplicated inside Google Cloud. Firewall logging rules provide traffic records, load-balancer certificates support secure application connections, and Cloud NAT gateways handle address translation. DNS forwarding policies therefore provide the mechanism for integrating VPC DNS resolution with external name servers.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>Which resource publishes a service for consumers through Private Service Connect?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Router<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service attachment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network endpoint group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud NAT configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A service attachment is used by a service producer to publish a supported service through Private Service Connect. Consumer networks can then connect to that published service through an appropriate Private Service Connect endpoint or related configuration. This model allows service providers to expose selected services privately without requiring broad network connectivity between the consumer and producer VPCs. Cloud Router handles route exchange, network endpoint groups define backend endpoints for supported load-balancing architectures, and Cloud NAT performs address translation. Service attachments therefore play a central role in the producer side of Private Service Connect.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>Which protocol enables dynamic route exchange with Cloud Router?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ICMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Border Gateway Protocol, or BGP, is used by Cloud Router to exchange routing information dynamically with supported peers. Through BGP sessions, Google Cloud and an external network can advertise reachable prefixes and learn routes from one another. This dynamic approach is valuable for hybrid connectivity because route changes can be propagated without manually updating static routes for every network change. ICMP is primarily used for diagnostic messaging, HTTPS provides encrypted application communication, and SNMP is commonly associated with device monitoring. BGP is therefore the protocol directly responsible for dynamic route exchange through Cloud Router.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>Which feature can restrict access to Google APIs using private network paths?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private Google Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Scheduler<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Private Google Access allows supported resources that lack external IP addresses to reach Google APIs and services through private connectivity. It is useful for workloads that need Google-managed services while maintaining a network architecture that avoids direct public addressing. The feature does not provide unrestricted access to the general internet; its purpose is specifically related to supported Google services and APIs. Cloud CDN accelerates content delivery, Cloud Scheduler executes scheduled tasks, and Cloud Logging collects log data. Private Google Access is therefore the appropriate capability when workloads need private access to Google APIs.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>Which network connectivity option provides a dedicated physical connection to Google Cloud?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dedicated Interconnect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private Service Connect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dedicated Interconnect provides a direct physical connection between an external network and Google Cloud through supported colocation facilities. It is intended for environments requiring private connectivity and can support substantial network capacity depending on the configured connection. Organizations can use VLAN attachments and Cloud Router to complete the logical networking configuration. Cloud VPN uses encrypted tunnels over an underlying network, Private Service Connect provides private service-level connectivity, and Cloud NAT performs address translation. Dedicated Interconnect is therefore the connectivity option specifically associated with a direct physical network connection to Google Cloud.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>Which feature provides metadata about traffic entering and leaving VM interfaces?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Flow Logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Armor rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS response policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Interconnect VLANs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPC Flow Logs provide metadata describing network traffic associated with supported network interfaces. Administrators can use this information to understand communication patterns, troubleshoot connectivity, investigate unexpected traffic, and support security monitoring. Flow logs do not capture every packet&#8217;s complete payload; instead, they provide structured information about network flows. Cloud Armor rules protect supported applications, DNS response policies influence name resolution, and Interconnect VLANs provide logical connectivity over Interconnect infrastructure. VPC Flow Logs are therefore the appropriate feature when administrators need visibility into network traffic metadata.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>Which load-balancing mechanism directs traffic to different backends according to hostnames?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Source NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Host-based routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static route priority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP route filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Host-based routing allows a supported HTTP(S) load-balancing configuration to direct requests toward different backend services based on the requested hostname. This is useful when multiple applications or services share a common load-balancing entry point but need separate backend destinations. Source NAT changes network address information, static route priority influences network forwarding decisions, and BGP route filtering controls advertised or accepted routes. Host-based routing operates on application request information and is therefore distinct from lower-level network routing mechanisms. It is especially useful for architectures hosting multiple domains or applications behind shared infrastructure.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>Which Google Cloud component can collect network performance telemetry?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Performance Monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Functions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secret Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Performance Monitoring provides visibility into network performance characteristics and can help administrators understand latency and connectivity behavior across supported environments. Such telemetry can assist with identifying performance degradation and determining whether issues are related to network paths or other components. Cloud Storage provides object storage, Cloud Functions supplies event-driven compute, and Secret Manager protects sensitive credentials and configuration values. Network Performance Monitoring is therefore the component focused specifically on observing network performance rather than storing objects, executing functions, or managing secrets.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>Which VPC design allows multiple projects to use one centrally administered network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Network Peering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared VPC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud VPN federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External HTTP load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Shared VPC enables multiple service projects to use subnets belonging to a centrally managed VPC network in a host project. This model separates project-level workload administration from centralized network administration. It can be useful for organizations that need consistent subnet management, routing, and network policies across several application projects. VPC Network Peering connects separate VPC networks but does not turn one project into the central host for shared subnets. Cloud VPN federation and external HTTP load balancing serve different purposes. Shared VPC is therefore the design specifically intended for centralized network usage across projects.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>Which tool can diagnose whether a route or firewall rule is blocking connectivity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Billing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connectivity Tests<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Composer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Artifact Registry<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Connectivity Tests can analyze network connectivity between supported endpoints and help identify configuration elements that influence packet delivery. Its analysis can consider routing, firewall behavior, and other relevant network configuration details. This makes it useful when an administrator needs to understand why a connection attempt is unsuccessful or determine whether the configured network path should work. Cloud Billing tracks costs, Cloud Composer manages workflow orchestration, and Artifact Registry stores software packages and container images. Connectivity Tests therefore provides a purpose-built mechanism for investigating network reachability problems.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>Which feature provides centralized control over routes across a resource hierarchy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hierarchical firewall policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Custom route advertisements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud NAT mappings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS peering configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Custom route advertisements allow Cloud Router to control which routes are advertised to connected BGP peers. This can provide administrators with more precise control over the prefixes visible to external networks. It is particularly useful in hybrid architectures where only selected Google Cloud routes should be announced. Hierarchical firewall policies control network access rather than route advertisements, Cloud NAT mappings handle address translation, and DNS peering configurations influence name resolution. Custom route advertisements therefore address routing visibility and advertisement behavior rather than firewall enforcement, NAT, or DNS operations.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>Which capability mirrors selected traffic to an inspection appliance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet Mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Address Translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Packet Mirroring creates copies of selected network traffic and sends those copies to a configured collector or inspection system. This can support security analysis, troubleshooting, monitoring, and specialized inspection use cases where examining packet-level information is necessary. Packet Mirroring differs from VPC Flow Logs because flow logs provide metadata rather than copies of actual traffic packets. Cloud DNS handles name resolution, Cloud CDN caches content, and Network Address Translation modifies address information. Packet Mirroring is therefore the capability designed for sending copies of selected traffic to an inspection or analysis system.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>Which routing mode allows subnet routes to be automatically available across VPC regions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Regional dynamic routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Global dynamic routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static next-hop routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy-based forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Global dynamic routing allows dynamically learned routes through Cloud Router to be available across regions within the VPC network, subject to the applicable Google Cloud routing behavior. This can simplify hybrid architectures where on-premises destinations need to be reachable from workloads located in multiple Google Cloud regions. Regional dynamic routing limits the scope of dynamically learned routes more narrowly. Static next-hop routing depends on explicitly configured routes, while policy-based forwarding follows configured traffic policies. Global dynamic routing is therefore useful when hybrid route availability needs to extend across VPC regions.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>Which service protects supported applications from distributed network and application attacks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Router<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Armor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Interconnect<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Armor provides security policies for supported Google Cloud load-balancing architectures and can help protect applications against various network and application-layer threats. Security policies can use configurable rules to control and inspect incoming requests before they reach protected backend services. Cloud DNS provides name resolution, Cloud Router handles dynamic route exchange, and Cloud Interconnect provides private connectivity. Cloud Armor is therefore the service specifically associated with protecting supported internet-facing applications and services through configurable edge security policies.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Google Professional Cloud Network Engineer Exam Dumps and Practice Test Dumps &nbsp; Question 381 Which Google Cloud resource provides an internal IP address for a regional subnet? Subnet Route policy VPN tunnel DNS zone Correct Answer: 1 Explanation: A subnet provides an IP address range within a VPC network and is associated with [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20123"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20123"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20123\/revisions"}],"predecessor-version":[{"id":20124,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20123\/revisions\/20124"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}