Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization is scaling hybrid connectivity between its on-premises data center and a Google Cloud Virtual Private Cloud (VPC) network. The current throughput requirements exceed the capacity of a single High Availability (HA) VPN gateway (250,000 packets per second per tunnel). The network security team must design an expanded VPN architecture that meets the following criteria:
Which architectural design should the team implement?
Deploy multiple HA VPN gateways and configure policy-based traffic selectors on each gateway matching specific /24 workload subnet ranges.
Deploy a single HA VPN gateway and augment bandwidth by adding route-based Classic VPN tunnels with custom static routes set to lower priority values.
Deploy multiple HA VPN gateways configured with an active/passive tunnel pair on each gateway, advertising prefixes with lower BGP MED values on active tunnels and higher MED values on passive tunnels.
Deploy multiple HA VPN gateways configured in an active/active routing topology across all gateways, advertise identical prefixes with equal BGP MED values across all active tunnels, and match the corresponding gateway interfaces.
Deploy multiple HA VPN gateways and configure policy-based traffic selectors on each gateway matching specific /24 workload subnet ranges.
Deploy a single HA VPN gateway and augment bandwidth by adding route-based Classic VPN tunnels with custom static routes set to lower priority values.
Deploy multiple HA VPN gateways configured with an active/passive tunnel pair on each gateway, advertising prefixes with lower BGP MED values on active tunnels and higher MED values on passive tunnels.
Deploy multiple HA VPN gateways configured in an active/active routing topology across all gateways, advertise identical prefixes with equal BGP MED values across all active tunnels, and match the corresponding gateway interfaces.
An active/active multi-gateway HA VPN architecture connects multiple Google Cloud HA VPN gateways to redundant on-premises peer VPN appliances. By configuring each tunnel pair in an active/active dynamic routing configuration over BGP with equal Multi-Exit Discriminator (MED) base priorities, Google Cloud distributes traffic across all active tunnels using Equal-Cost Multi-Path (ECMP) hashing.
Unlike multi-gateway active/passive configurations—which suffer from failover deadlocks where standby tunnels remain unused until all active tunnels across all gateways fail—an active/active setup across multiple gateways ensures all provisioned bandwidth is actively utilized while maintaining graceful degradation during link failures.