Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise has established hybrid connectivity between its on-premises data center and a central Google Cloud Virtual Private Cloud (VPC) network using Dedicated Interconnect.
A partner team hosts a proprietary analytics service behind an internal Network Load Balancer in a separate, isolated VPC project. You need to enable private access to this analytics service from both on-premises systems and cloud instances located across multiple Google Cloud regions.
Your solution must meet the following requirements:
Which network architecture should you implement?
Establish VPC Network Peering between the central VPC and the partner VPC, and configure custom route exchange with transitive routing enabled.
Deploy an HA VPN gateway tunnel between the central VPC and the partner VPC, and configure BGP route advertisements for the analytics service subnet.
Attach the partner's project as a Shared VPC service project to the central host project, and provision the service on a dedicated subnet.
Publish the analytics service using a Private Service Connect service attachment, and create a Private Service Connect endpoint with global access enabled in the central VPC.
Establish VPC Network Peering between the central VPC and the partner VPC, and configure custom route exchange with transitive routing enabled.
Deploy an HA VPN gateway tunnel between the central VPC and the partner VPC, and configure BGP route advertisements for the analytics service subnet.
Attach the partner's project as a Shared VPC service project to the central host project, and provision the service on a dedicated subnet.
Publish the analytics service using a Private Service Connect service attachment, and create a Private Service Connect endpoint with global access enabled in the central VPC.
Private Service Connect (PSC) is a cloud-native networking feature that allows service producers to publish services via an internal load balancer, and service consumers to access those services privately using internal IP addresses assigned to endpoints or forwarding rules within their own VPC network. When global access is enabled on a consumer PSC endpoint, clients in any Google Cloud region as well as hybrid clients connecting from on-premises networks via Cloud Interconnect or Cloud VPN can route traffic directly to the endpoint.
Unlike VPC Network Peering, which requires unique, non-overlapping IP space and exposes entire network topologies, PSC establishes targeted, unidirectional service access. Combined with global access, it fulfills all multi-region and hybrid requirements natively without the operational burden of managing routing appliances.