Soru

Zorluk: ZorConfiguring Network Topology and VPC Infrastructure

An enterprise organization is provisioning a global multi-project Google Cloud network topology across `us-central1` and `europe-west1`. The architecture utilizes a Shared VPC Host Project connecting multiple Service Projects, along with an on-premises data center connected via Cloud Interconnect. The networking team must ensure continuous dynamic route propagation across all regions and hybrid links, alongside secure private connectivity to Google Cloud APIs from workloads that lack external IP addresses. Which TWO configuration steps must be implemented to satisfy these networking and access requirements? (Select TWO.)

  1. Set the VPC network dynamic routing mode to Global and configure Cloud Router in the Host VPC to dynamically exchange BGP routes across regions and hybrid connections.Cevap
  2. Enable Private Google Access on internal subnets and provision Private Service Connect endpoints for accessing Google Cloud APIs using internal IP addresses.Cevap
  3. C
    Configure VPC Network Peering between Service Project A and Service Project B through the central Host VPC, relying on host routing to forward traffic transitively between service workloads.
  4. D
    Replace the Cloud Interconnect connection with an High Availability (HA) VPN gateway using static routing to support hybrid traffic bandwidth requirements exceeding 10 Gbps.
  5. E
    Disable control plane authorized networks on private GKE clusters in service subnets so administrative traffic from the host network can reach master endpoints without IP range restrictions.

Cevap

The correct architecture requires setting the VPC dynamic routing mode to Global with Cloud Router BGP advertising across regions and hybrid links, and enabling Private Google Access alongside Private Service Connect endpoints for secure internal Google API routing.
Global Dynamic Routing enables Cloud Routers in a VPC to learn and advertise routes across all GCP regions and hybrid Interconnect attachments dynamically. In addition, enabling Private Google Access on subnets and configuring Private Service Connect endpoints allows internal VM workloads without external IP addresses to privately access Google API endpoints safely over private RFC 1918 space.

Adım Adım Çözüm

1
Analyze dynamic routing requirements for multi-region and hybrid interconnect topology.
Determined that Regional Dynamic Routing limits route visibility to the local region, whereas Global Dynamic Routing allows Cloud Router to propagate routes across all GCP regions and on-premises BGP sessions.
Global dynamic routing is required for seamless inter-region dynamic route propagation across Dedicated/Partner Interconnect.
2
Evaluate private connectivity options for Google APIs.
Configuring Private Google Access on subnets and deploying Private Service Connect endpoints fulfills the requirement to access Google APIs securely via internal IP space.
Workloads without public IP addresses depend on Private Google Access or Private Service Connect for private API ingestion.
3
Evaluate distractor configurations against Google Cloud VPC constraints.
Identified that VPC Peering transitivity assumptions fail because peering does not support transitive routing; HA VPN cannot meet >10 Gbps bandwidth requirements; and disabling GKE authorized networks breaks security posture.
Eliminating invalid networking choices based on non-transitive peering rules and throughput limits.

Anahtar Kavram

Global Dynamic Routing and Private Access Topology in Google Cloud VPCs
Bu soruyu puanla