Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
A financial enterprise requires a secure, high-bandwidth connection between its on-premises data center and a Google Cloud VPC network. Compliance regulations mandate that all data in transit must be encrypted using IPsec tunnels, and the architecture must guarantee a 99.99% availability Service Level Agreement (SLA) with automated dynamic route propagation via BGP.
Which configuration should the network security engineer implement to satisfy these requirements?
HA VPN over Cloud Interconnect is an enterprise hybrid networking architecture that establishes secure, hardware-accelerated IPsec encrypted tunnels directly over private, dedicated or partner physical interconnects. It pairs the high bandwidth, low latency, and deterministic routing of Cloud Interconnect with the end-to-end payload encryption of High Availability (HA) Cloud VPN.
This approach strictly follows the architectural requirements for HA VPN over Cloud Interconnect. Google Cloud explicitly requires a dedicated Cloud Router for the overlay HA VPN tunnels separate from the Cloud Router managing the underlying Interconnect VLAN attachment BGP sessions.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.