Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise requires a secure, high-bandwidth connection between its on-premises data center and a Google Cloud VPC network. Compliance regulations mandate that all data in transit must be encrypted using IPsec tunnels, and the architecture must guarantee a 99.99% availability Service Level Agreement (SLA) with automated dynamic route propagation via BGP.
Which configuration should the network security engineer implement to satisfy these requirements?
Provision standard unencrypted VLAN attachments on Dedicated Interconnect and configure a single shared Cloud Router to manage BGP sessions for both the VLAN attachments and the overlay HA VPN tunnels.
Provision two encrypted Cloud Interconnect VLAN attachments, create an initial Cloud Router for the Interconnect BGP sessions, deploy an HA VPN gateway with two tunnels (one per interface) mapped to the attachments, and create a separate, dedicated Cloud Router to manage the HA VPN BGP sessions.
Create an external peer VPN gateway configured with FOUR_IPS_REDUNDANCY, establish policy-based static routes, and bypass Cloud Router to establish direct IPsec associations over standard VLAN attachments.
Deploy an HA VPN gateway with a single active tunnel configured to an external peer VPN gateway using the SINGLE_IP_INTERNALLY_REDUNDANT redundancy type and static route priority on Cloud Router.
Provision standard unencrypted VLAN attachments on Dedicated Interconnect and configure a single shared Cloud Router to manage BGP sessions for both the VLAN attachments and the overlay HA VPN tunnels.
Provision two encrypted Cloud Interconnect VLAN attachments, create an initial Cloud Router for the Interconnect BGP sessions, deploy an HA VPN gateway with two tunnels (one per interface) mapped to the attachments, and create a separate, dedicated Cloud Router to manage the HA VPN BGP sessions.
HA VPN over Cloud Interconnect is an enterprise hybrid networking architecture that establishes secure, hardware-accelerated IPsec encrypted tunnels directly over private, dedicated or partner physical interconnects. It pairs the high bandwidth, low latency, and deterministic routing of Cloud Interconnect with the end-to-end payload encryption of High Availability (HA) Cloud VPN.
This approach strictly follows the architectural requirements for HA VPN over Cloud Interconnect. Google Cloud explicitly requires a dedicated Cloud Router for the overlay HA VPN tunnels separate from the Cloud Router managing the underlying Interconnect VLAN attachment BGP sessions.
Create an external peer VPN gateway configured with FOUR_IPS_REDUNDANCY, establish policy-based static routes, and bypass Cloud Router to establish direct IPsec associations over standard VLAN attachments.
Deploy an HA VPN gateway with a single active tunnel configured to an external peer VPN gateway using the SINGLE_IP_INTERNALLY_REDUNDANT redundancy type and static route priority on Cloud Router.