Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your organization is deploying a hybrid architecture connecting an on-premises data center with Google Cloud VMware Engine (GCVE) and native Google Cloud Virtual Private Cloud (VPC) networks hosting Google Kubernetes Engine (GKE) and Compute Engine workloads.
The network team plans to provision dozens of NSX-T segments across multiple application tiers. You need to design the routing topology between VMware Engine, native VPC services, and the on-premises environment to maintain scalable routing, prevent route table exhaustion, and adhere to recommended architectural best practices.
Which set of routing and NSX-T network configurations should you implement?
Establish separate VPC Network Peering connections for each NSX-T segment and configure individual policy-based routes (PBR) on Compute Engine VMs to route VMware traffic
Allocate contiguous IP address space for NSX-T segments, configure route summarization at the Tier-0 gateway, and apply a route map when redistributing static routes into BGP to prevent 0.0.0.0/0 from being advertised
Assign non-contiguous /24 subnets across NSX-T segments, export discrete /32 host routes from the Tier-0 gateway, and redistribute all static default routes into BGP sessions
Connect each NSX-T segment directly to Cloud Interconnect using dedicated VLAN attachments and disable dynamic BGP peering on the Tier-0 gateway
Establish separate VPC Network Peering connections for each NSX-T segment and configure individual policy-based routes (PBR) on Compute Engine VMs to route VMware traffic
Allocate contiguous IP address space for NSX-T segments, configure route summarization at the Tier-0 gateway, and apply a route map when redistributing static routes into BGP to prevent 0.0.0.0/0 from being advertised
Google Cloud VMware Engine (GCVE) integrates VMware Software-Defined Data Center (SDDC) components—such as NSX-T Data Center—directly with Google Cloud's high-speed software-defined network. Within GCVE, routing between logical segments and the rest of the network is managed hierarchically via Tier-1 and Tier-0 gateways, which peer dynamically using Border Gateway Protocol (BGP) with Cloud Router across private service access.
0.0.0.0/0 during static-to-BGP redistribution prevents an accidental default route override, ensuring predictable routing behavior between on-premises and Google Cloud.This approach aligns strictly with Google Cloud networking best practices for GCVE, optimizing route table capacity while preserving seamless Layer 3 connectivity across hybrid environments.
Assign non-contiguous /24 subnets across NSX-T segments, export discrete /32 host routes from the Tier-0 gateway, and redistribute all static default routes into BGP sessions
Connect each NSX-T segment directly to Cloud Interconnect using dedicated VLAN attachments and disable dynamic BGP peering on the Tier-0 gateway