Pro Network Engineer Cert Flashcards

1
Q

What are the three types of networks?

A

Default , auto, and custom

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the default network?

A

It is an auto-mode network with one subnet per region, fixed /20 per region, expandable to /16. Comes with default firewall rules.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is an auto-mode network?

A

One subnet per region, fixed /20 per region, expandable to /16. Regional IP allocation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a custom network?

A

No default subnets created, full control of IP ranges, regional IP allocation, expandable to any RFC 1918 size

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Are subnets zonal or regional or global?

A

They are regional - one subnet can span multiple zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the first available address in a subnet? What are the ones before it for?

A

.0 is for the network, .1 is for the gateway, so .2 is the first available

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Does a VM know its external address?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Are public DNS records published automatically?

A

Nope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the SLA for Cloud DNS?

A

100%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How do you assign multiple IP addresses to a VM? Why would you do this?

A

Can assign multiple through multiple NICs. You can use this to bridge multiple networks or have management network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How do you assign a range of IP addresses to a VM? Why would you do this?

A

Can assign a range through alias IPs. Can assign range for giving services (i.e. containers) their own IP addresses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is default routing?

A

Every network has a default route to get out of the network. Routes default to get to the other subnets as well.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Where are firewall rules applied?

A

At the instance level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Are firewall rules stateful?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the default firewall rules?

A

DENY ALL ingress and ALLOW ALL egress

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How many NICs can a VM have?

A

At least 2. After 2, it’s the number of CPUs until 8. Max is 8.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

When can you add, change, or delete multiple NICs?

A

Only at instance creation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which NIC does internal DNS associate to?

A

nic0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What are the restrictions for IPs/networks for multiple NICs

A

Each NIC is on a different network, IP ranges cannot overlap at all, networks must already exist before being configured

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are the basic roles for networking? What can they do?

A

Network viewer - read-only access to all networking
Network admin - permissions to create/modify/delete except for firewall rules and SSL certs
Security admin - can create/modify/delete SSL certs and firewall rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What can you specify for targets with firewall rules?

A

All instances, specified target tags, specified service accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What can you specify for sources with firewall rules?

A

IP ranges, subnets, source tags, and service accounts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What three roles are needed to provision and manage a shared VPC?

A

Org admin -> Shared VPC Admin -> Service Project Admin

24
Q

Is transitive peering supported?

A

Nope

25
Q

What is the advantage of shared VPC over VPC network peering?

A

Centralized network admin, simplifies internal DNS

26
Q

What is the advantage of VPC network peering over shared VPC?

A

Can be used across orgs, multiple projects, or within a single project. Decentralized network admin if you like that. Quotas aren’t used as quickly if you can use multiple projects.

27
Q

Can you peer with a shared VPC?

A

Yes

28
Q

How are DNS names handled across VPC peering?

A

DNS names are NOT transferred across with VPC peering

29
Q

What policies are available for autoscaling a managed instance group?

A

CPU utilization, load balancing capacity, monitoring metrics, and queue-based workloads

30
Q

What are the global load balancing services?

A

HTTP(s) Load Balancer, TCP Proxy, and SSL Proxy

31
Q

What are the regional load balancing services?

A

Network TCP/UDP load balancer, internal load TCP/UDP load balancing

32
Q

Where is IPv6 supported?

A

HTTP(s) Load Balancer, TCP Proxy, and SSL Proxy

33
Q

What are the key features of a global HTTP(s) load balancer?

A

Global load balancing, anycast IP, does auto-scaling, can have backend services with health chekcs, session affinity (with timeouts), and one-or-more backends

34
Q

What three things does a backend need to be configured?

A

An instance group, a balancing mode (CPU or RPS), and a capacity scaler (ceiling % of CPU/rate targets)

35
Q

What is cloud armor?

A

Protects load balancers from DDOS, can blacklist or whitelist IPs, can configure the deny rule, can set priority to rules

36
Q

What are the key features of an SSL proxy?

A

Global load balancing for encrypted, non-HTTP traffic, terminates SSL, can do intelligent routing and certificate management, auto security patching

37
Q

What are the key features of a TCP proxy?

A

Global load balancing for non-encrypted, non-HTTP traffic, terminates TCP connections, intelligent routing and security patching

38
Q

What are the key features of a network load balancer?

A

Regional load balancing for TCP/UDP (non-proxied), forwarding rules, has instance groups and target pools

39
Q

What are the key features of an ILB

A

Similar to NLB but internal, has fully distributed software defined load balancing

40
Q

How do L2 connections connect to GCP?

A

They connect a VLAN to a specific GCP network

41
Q

What routing does a VPN support?

A

Static routing or dynamic routes via BGP with a cloud router

42
Q

What is the VPN gateway?

A

A regional resource that uses external IP address

43
Q

Are any other IPs needed for a VPN setup?

A

Need to add separate link-local IP address to establish BGP for dynamic routing

44
Q

What are the SLAs for dedicated interconnect?

A

99.9% for single connection, 99.99% for double in different regions

45
Q

What is direct peering?

A

Direct connection to Google for access to Google services (non-customer GCP)

46
Q

What do you do if you cannot meet the peering requirements?

A

Partner peering

47
Q

What is the SLA for peering?

A

None

48
Q

When are you charged for networking?

A

Egress to anything out of the zone/region but within-region and global Google products

49
Q

What sacrifices are made for the standard network tier?

A

No global load balancing, no global SLA, more network hops because it doesn’t use GCPs backbone

50
Q

What is private Google access?

A

VMs with only private IPs can still access Google services (like storage buckets), granted at the subnet level

51
Q

What is the benefit of cloud NAT over traditional NAT?

A

It has 1 fewer hop because it’s software defined at the instance level

52
Q

What is manual mode vs auto mode for the NAT?

A

Manually specify IPs for full control or automatically do it with auto-scaling

53
Q

How do you prevent deployment manager from deploying sequential things in parallel?

A

Add a reference to the previous step in the next step

54
Q

What are VPC Flow Logs?

A

A sample of logs flowing to/from VMs on the network, sampled every 5 seconds with no latency hit, enabled at the subnet

55
Q

What is included in the VPC flow log?

A

IPs/ports/protocol, plus start/end times, bytes, instance details, vpc details, geography