GCP Professional Cloud Security Engineer Practice Question

Your company must establish encrypted connectivity between its on-premises data center, which has two border routers operating in active/active mode, and a single Google Cloud VPC. The networking team requires Google's 99.99 % Cloud VPN SLA and automatic failover if either an on-prem router or a Google zone becomes unavailable. Which design satisfies these requirements while following Google best practices?

  • Create one HA VPN gateway in your VPC with two interfaces located in separate zones; configure a Cloud Router and build one BGP tunnel on each interface, terminating on different on-prem routers.

  • Configure an HA VPN gateway with two interfaces but place both dynamic BGP tunnels on interface 0, terminating on the same on-prem router for simplicity.

  • Provision a single HA VPN gateway with only one interface and establish two policy-based IPsec tunnels (static routes) to each on-prem router.

  • Deploy two Classic VPN gateways in different Google Cloud regions, each with a single static route-based tunnel to the same on-prem router, and rely on your internal IGP for failover.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot