professional-cloud-data-engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise data engineering team is establishing a secure hybrid data ingestion pipeline. On-premises server fleets need to stream large volumes of telemetry data directly into regional Google Cloud data service APIs across a Dedicated Interconnect connection.
The network architecture must meet the following constraints:
Which combination of network configurations should the team deploy?
Set up a global external Application Load Balancer with a serverless NEG targeting Cloud Run, configure Private Google Access on the subnet, and create an on-premises static route pointing to the default internet gateway.
Configure an external Application Load Balancer with an internet NEG pointing to the public Google API endpoints, deploy a Cloud NAT gateway with static IP addresses, and publish external public DNS A records pointing to the Cloud NAT public IP.
Create a Private Service Connect NEG pointing to the regional Google API service attachment, attach it to the internal Application Load Balancer backend service, advertise the forwarding rule subnet via Cloud Router BGP, configure a Cloud DNS private zone pointing to the load balancer IP, and create a Cloud DNS inbound server policy to forward on-premises DNS queries to the inbound forwarder entry point.
Deploy a regional external proxy Network Load Balancer with zonal hybrid NEGs, configure a Cloud DNS outbound server policy pointing to on-premises name servers, and disable BGP route advertisements on Cloud Router.
Set up a global external Application Load Balancer with a serverless NEG targeting Cloud Run, configure Private Google Access on the subnet, and create an on-premises static route pointing to the default internet gateway.
Configure an external Application Load Balancer with an internet NEG pointing to the public Google API endpoints, deploy a Cloud NAT gateway with static IP addresses, and publish external public DNS A records pointing to the Cloud NAT public IP.
Create a Private Service Connect NEG pointing to the regional Google API service attachment, attach it to the internal Application Load Balancer backend service, advertise the forwarding rule subnet via Cloud Router BGP, configure a Cloud DNS private zone pointing to the load balancer IP, and create a Cloud DNS inbound server policy to forward on-premises DNS queries to the inbound forwarder entry point.
Private Service Connect (PSC) Network Endpoint Groups (NEGs) combined with an internal Application Load Balancer (ILB) and Cloud DNS inbound server policies allow private, governed hybrid access from on-premises networks directly to regional Google APIs and managed services over private interconnects.
pubsub.REGION.rep.googleapis.com).This pattern strictly satisfies all private connectivity, dynamic BGP advertisement, Layer 7 routing, and hybrid DNS resolution requirements using standard, fully managed Google Cloud networking primitives.
Deploy a regional external proxy Network Load Balancer with zonal hybrid NEGs, configure a Cloud DNS outbound server policy pointing to on-premises name servers, and disable BGP route advertisements on Cloud Router.