You have several VMs across multiple VPCs in your cloud environment that require access to internetendpoints. These VMs cannot have public IP addresses due to security policies, so you plan to use CloudNAT to provide outbound internet access. Within your VPCs, you have several subnets in each region. Youwant to ensure that only specific subnets have access to the internet through Cloud NAT. You want to avoidany unintentional configuration issues caused by other administrators and align to Google-recommendedpractices. What should you do?
Recently, your networking team enabled Cloud CDN for one of the external-facing services that is exposed
through an external Application Load Balancer. The application team has already defined which content
should be cached within the responses. Upon testing the load balancer, you did not observe any change in
performance after the Cloud CDN enablement. You need to resolve the issue. What should you do?
Your organization recently re-architected your cloud environment to use Network Connectivity Center.
However, an error occurred when you tried to add a new VPC named vpc-dev as a spoke. The error indicated
that there was an issue with an existing spoke and the IP space of a VPC named vpc-pre-prod. You must
complete the migration quickly and efficiently. What should you do?
You are designing a packet mirroring policy as pan of your network security architecture for your gaming
workload. Your Infrastructure is located in the us-west2 region and deployed across several zones: us-west2-
a. us-west2-b. and us-west2-c The Infrastructure Is running a web-based application on TCP ports 80 and 443
with other game servers that utilize the UDP protocol. You need to deploy packet mirroring policies and
collector instances to monitor web application traffic while minimizing inter-zonal network egress costs.
Following Google-recommended practices, how should you deploy the packet mirroring policies and collector
instances?