PCNE Practice Exam: Professional Cloud Network Engineer
GCP networking: VPCs, Cloud Interconnect, global load balancing, and DNS done right.
What you'll be tested on
- VPC Design
- Hybrid Connectivity
- Load Balancing
- Network Security
- Monitoring and Optimization
Sample PCNE questions
You need to restrict access to your Google Cloud load-balanced application so that only specific IP addresses can connect. What should you do?
- Create a secure perimeter using the Access Context Manager feature of VPC Service Controls and restrict access to the source IP range of the allowed clients and Google health check IP ranges.
- Create a secure perimeter using VPC Service Controls, and mark the load balancer as a service restricted to the source IP range of the allowed clients and Google health check IP ranges.
- Tag the backend instances "application," and create a firewall rule with target tag "application" and the source IP range of the allowed clients and Google health check IP ranges.
- Label the backend instances "application," and create a firewall rule with the target label "application" and the source IP range of the allowed clients and Google health check IP ranges.
Show answer
C — Tag the backend instances "application," and create a firewall rule with target tag "application" and the source IP range of the allowed clients and Google health check IP ranges.VPC firewall rules are the correct tool for restricting which source IP ranges can reach backend instances. Firewall rules are applied to instances using network tags (not labels), so tagging the backends "application" and creating a rule with that target tag and the allowed client source ranges plus Google's health check ranges (35.191.0.0/16 and 130.211.0.0/22) works. Health check ranges must be allowed or the load balancer stops sending traffic. Labels are not usable as firewall targets, ruling out D. VPC Service Controls protects Google API access, not load-balanced application traffic, ruling out A and B.
Your end users are located in close proximity to us-east1 and europe-west1. Their workloads need to communicate with each other. You want to minimize cost and increase network efficiency. How should you design this topology?
- Create 2 VPCs, each with their own regions and individual subnets. Create 2 VPN gateways to establish connectivity between these regions.
- Create 2 VPCs, each with their own region and individual subnets. Use external IP addresses on the instances to establish connectivity between these regions.
- Create 1 VPC with 2 regional subnets. Create a global load balancer to establish connectivity between the regions.
- Create 1 VPC with 2 regional subnets. Deploy workloads in these subnets and have them communicate using private RFC1918 IP addresses.
Show answer
D — Create 1 VPC with 2 regional subnets. Deploy workloads in these subnets and have them communicate using private RFC1918 IP addresses.A single VPC is global in Google Cloud, so one VPC with regional subnets in us-east1 and europe-west1 lets instances communicate over Google's private backbone using RFC1918 internal IPs with no gateways, VPNs, or external IPs. This is the cheapest and most efficient design. Two VPCs with VPN gateways add cost and tunnel overhead. External IPs incur egress charges and traverse the public internet. A global load balancer distributes external client traffic to backends; it is not a mechanism for inter-region workload-to-workload connectivity. D is correct.
Your organization is deploying a single project for 3 separate departments. Two of these departments require network connectivity between each other, but the third department should remain in isolation. Your design should create separate network administrative domains between these departments. You want to minimize operational overhead. How should you design the topology?
- Create a Shared VPC Host Project and the respective Service Projects for each of the 3 separate departments.
- Create 3 separate VPCs, and use Cloud VPN to establish connectivity between the two appropriate VPCs.
- Create 3 separate VPCs, and use VPC peering to establish connectivity between the two appropriate VPCs.
- Create a single project, and deploy specific firewall rules. Use network tags to isolate access between the departments.
Show answer
C — Create 3 separate VPCs, and use VPC peering to establish connectivity between the two appropriate VPCs.Creating three separate VPCs gives each department its own network administrative domain, satisfying the isolation requirement for the third department. Peering only the two VPCs that need connectivity provides private, non-transitive communication between them while leaving the third isolated. Shared VPC within one host project does not create separate administrative domains the same way and is more complex than needed for a single project. Cloud VPN works but adds tunnel cost, encryption overhead, and operational complexity that peering avoids. Firewall rules with network tags within one network do not provide true network-level administrative separation. C is correct.
Access plans
| Access | Price |
|---|---|
| 3 months | |
| 1 year | |
| Lifetime |
Free preview inside — try 5 questions before you pay anything.
FAQ
How many practice questions are in this PCNE bank?
315 questions covering the current PCNE Professional Cloud Network Engineer syllabus, every one with the correct answer and an explanation.How long is the real PCNE exam?
The official PCNE exam gives you 120 minutes. Our timed exam mode uses the same limit so the pace feels familiar.What does PCNE access cost?
Plans start at $3.99 for 3 months. One payment, no subscription — and far cheaper than retaking the real exam.