Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is architecting a mission-critical hybrid network topology connecting an on-premises data center to Google Cloud. The architecture must satisfy the following technical and operational requirements:
Which hybrid networking design should you implement?
Deploy a transit hub VPC with an internal passthrough Network Load Balancer fronting a managed instance group of NVAs as the next hop for peered spoke VPCs, terminate redundant Cloud Interconnect VLAN attachments in the transit network, and configure Cloud Routers with summary custom route advertisements.
Deploy an external Application Load Balancer in the transit VPC to inspect internal RFC 1918 traffic, and configure Cloud Routers to redistribute raw default static routes (0.0.0.0/0) directly into on-premises BGP tables without filtering.
Deploy a single Compute Engine VM configured as an NVA router in the hub VPC, use static host routes pointing to that VM's IP address, and disable Cloud Router BGP dynamic routing.
Connect each spoke VPC directly to on-premises routers using individual single-tunnel Cloud VPN gateways, assign a public IP to each workload VM, and advertise specific /32 host routes via BGP.
Deploy a transit hub VPC with an internal passthrough Network Load Balancer fronting a managed instance group of NVAs as the next hop for peered spoke VPCs, terminate redundant Cloud Interconnect VLAN attachments in the transit network, and configure Cloud Routers with summary custom route advertisements.
This architecture establishes a centralized transit hub-and-spoke topology that uses Cloud Interconnect for high-throughput, redundant hybrid connectivity. It leverages an internal passthrough Network Load Balancer as a next hop to distribute traffic evenly across a managed instance group (MIG) of firewall Network Virtual Appliances (NVAs), while using Cloud Router summary custom advertisements to manage BGP prefix scale.
Combining a transit hub VPC with an internal load balancer as the next hop provides the resilience, scalability, and deep inspection required by enterprise landing zones without compromising routing stability.
Deploy an external Application Load Balancer in the transit VPC to inspect internal RFC 1918 traffic, and configure Cloud Routers to redistribute raw default static routes (0.0.0.0/0) directly into on-premises BGP tables without filtering.
Deploy a single Compute Engine VM configured as an NVA router in the hub VPC, use static host routes pointing to that VM's IP address, and disable Cloud Router BGP dynamic routing.
Connect each spoke VPC directly to on-premises routers using individual single-tunnel Cloud VPN gateways, assign a public IP to each workload VM, and advertise specific /32 host routes via BGP.