Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise uses a hub-and-spoke network topology on Google Cloud. The central hub-vpc is connected to multiple departmental spoke VPCs via VPC Network Peering, with custom route exchange enabled to share internal routes across networks.
A security engineer is deploying a private VPC-native Google Kubernetes Engine (GKE) cluster in spoke-vpc-a. The cluster deployment fails during creation with an IP address conflict error, even though the selected /28 control plane IP range does not overlap with any primary or secondary subnet ranges locally configured inside spoke-vpc-a.
What is the root cause of this deployment failure, and how should the engineer resolve it?
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.