Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is planning a large-scale migration of on-premises workloads and databases across multiple departments to Google Cloud. The migration strategy requires a secure, scalable network architecture that satisfies the following criteria:
Which network architecture should you design to meet these requirements?
Deploy independent VPC networks in each departmental project, connect each VPC directly to on-premises using separate Cloud VPN tunnels with static routing, and assign instance tags to control traffic flow.
Deploy a single Shared VPC host project with dynamic routing set to regional on the Cloud Router, and create VPC Network Peering connections between all departmental projects and the host project.
Deploy a Shared VPC host project with dynamic routing set to global on the Cloud Router, attach departmental service projects, and provision Cloud Interconnect VLAN attachments in the Shared VPC host project.
Deploy auto-mode VPC networks in each departmental project, deploy a multi-NIC VM instance inside each project acting as an edge router, and connect each VM to on-premises using Private Service Connect.
Deploy independent VPC networks in each departmental project, connect each VPC directly to on-premises using separate Cloud VPN tunnels with static routing, and assign instance tags to control traffic flow.
Deploy a single Shared VPC host project with dynamic routing set to regional on the Cloud Router, and create VPC Network Peering connections between all departmental projects and the host project.
Deploy a Shared VPC host project with dynamic routing set to global on the Cloud Router, attach departmental service projects, and provision Cloud Interconnect VLAN attachments in the Shared VPC host project.
Shared VPC allows an organization to connect resources from multiple service projects to a common, centrally managed Virtual Private Cloud (VPC) network. When combined with Cloud Interconnect and a Cloud Router configured for global dynamic routing, the Cloud Router uses External Border Gateway Protocol (eBGP) to advertise all subnets across all regions within the VPC to the on-premises network while dynamically learning on-premises routes.
This architecture is the recommended best practice for enterprise hybrid deployments in Google Cloud. It provides strict security and operational isolation between the network administration team and application teams while establishing a unified, high-performance routing fabric across multiple regions.
Deploy auto-mode VPC networks in each departmental project, deploy a multi-NIC VM instance inside each project acting as an edge router, and connect each VM to on-premises using Private Service Connect.