Google CloudProfessional

Professional Cloud Network Engineer

PCNE

Implement and manage network architectures on Google Cloud, including hybrid connectivity and network security.

Duration
120 min
Exam questions
50–60
Passing score
Pass / Fail (undisclosed)
Exam fee
$200
Question formats:Multiple choiceMultiple response
Free plan
3 free papers
Free account
Mocks locked
Pro only
Upgrade to Pro
Every paper and mock exam.
See Pro

Start with free papers Free

You get 3 free practice papers with your plan.

Free
Mixed paper 1
Domain 1 · 25 questions
Free
Mixed paper 2
Domain 1 · 25 questions
Free
Mixed paper 3
Domain 1 · 25 questions

Domain papers 532 questions

Free
Mixed paper 1
25 questions · 60 min
Free
Mixed paper 2
25 questions · 60 min
Free
Mixed paper 3
25 questions · 60 min
Pro
Mixed paper 4
25 questions · 60 min
Pro
Mixed paper 5
22 questions · 53 min

Mock exams Pro

Full-length, exam-like practice tests. Available with Pro.

Mock exam 1
55 questions · 120 min
Mock exam 2
55 questions · 120 min
Mock exam 3
55 questions · 120 min

Try a sample question

All 10 sample questions →
Question 1Designing and planning a Google Cloud VPC network

Following an acquisition, Sandrine Foods must connect a manufacturer whose data centres consume almost all of 10.0.0.0/8, including ranges already used by Sandrine's production VPC. Re-addressing either estate is impossible because of embedded shop-floor controllers. New Google Cloud subnets are needed for the acquired workloads, which must initiate connections to a shared inventory service in Sandrine's existing VPC. What should you do?

  1. A.

    Allocate the new subnets from the RFC 6598 range 100.64.0.0/10, which Google Cloud supports as a privately used non-RFC 1918 subnet range, and peer that VPC with Sandrine's production VPC.

  2. B.

    Re-address the acquired company's shop-floor networks into 172.16.0.0/12 before the first migration wave.

  3. C.

    Create a VPC Network Peering connection between the two networks and enable the option to allow overlapping subnet ranges.

  4. D.

    Assign external IPv6 addresses to the migrated workloads and reach the inventory service through an external Application Load Balancer over the public internet, restricted by a Google Cloud Armor allowlist.

Show answer

Answer: A

Google Cloud subnets accept non-RFC 1918 ranges, so carving the new subnets from 100.64.0.0/10 avoids the collision entirely and lets the two VPCs peer.

  • A. Google Cloud VPC subnets accept non-RFC 1918 ranges such as 100.64.0.0/10, giving the migrated workloads address space that collides with neither estate and peers cleanly.
  • B. Re-addressing the shop-floor networks is exactly the project the business ruled out because of the embedded controllers.
  • C. VPC Network Peering explicitly refuses to establish when subnet ranges overlap and offers no setting to permit the overlap.
  • D. Fronting an internal inventory service with an internet-facing load balancer adds public exposure and latency when private, non-overlapping connectivity is available.

What's on the exam

6 domains · 22 task statements, straight from the official exam guide (as of 2026-09-14).

  1. 1.1Designing an overall network architecture
    • Differentiating between network tiers (e.g., Premium and Standard).
    • Designing for high availability, failover, disaster recovery, and scale.
    • Designing the DNS topology (e.g., on-premises and Cloud DNS).
    • Choosing an appropriate load balancer for network implementation.
    • Planning for Google Kubernetes Engine (GKE) networking (e.g., secondary ranges, scale potential based on IP address space, and access to GKE control plane).
    • Identifying the most appropriate Identity and Access Management (IAM) roles suited to specific network architecture designs (e.g. load balancer provisioning and Shared VPC subnet permissions).
    • Planning for connectivity to managed services (e.g., private services access, Private Service Connect [PSC], and Serverless VPC Access).
    • Planning for quotas and limits.
  2. 1.2Designing VPC networks
    • Choosing the VPC type and quantity (e.g., standalone or Shared VPC and the number of VPC environments).
    • Determining how the networks interconnect based on requirements (e.g., VPC Network Peering, network connectivity [mesh and star topology] with Network Connectivity Center, and PSC).
    • Planning the IP address management (IPAM) strategy (e.g., subnets, IPv6, bring your own IP, privately used public IP [PUPI], Private NAT, non-RFC 1918 addresses, managed services, and IPAM automation techniques).
    • Planning a global or regional network environment (or variations of these).
    • Determining the correct maximum transmission unit (MTU) sizing for VPC for workloads.
    • Planning third-party device insertion (e.g., network virtual appliance) with custom routes (static or policy-based) and load balancing.
  3. 1.3Designing a resilient and performant hybrid and multi-cloud network
    • Designing for hybrid (e.g., on-premises and cloud, branch office) connectivity, including bandwidth and security constraints (e.g., Dedicated Interconnect, Partner Interconnect, Cloud VPN, and SD-WAN appliances).
    • Designing for multicloud connectivity (e.g., Cloud VPN and Cross-Cloud Interconnect).
    • Choosing when to use Direct Peering or Verified Peering Provider.
    • Designing high-availability and disaster recovery connectivity strategies for multiple regions (e.g., regional or global dynamic routing mode).
    • Accessing multiple VPCs from on-premises locations (e.g., Shared VPC, multi-VPC peering, and Network Connectivity Center topologies).
    • Accessing Google services like Vertex AI and application programming interfaces (APIs) privately from on-premises locations.
    • Accessing managed services through PSC and VPC Network Peering connections (e.g., private services access).
    • Designing the IP address space across on-premises locations and cloud environments (e.g., internal ranges, planning to avoid overlaps, and Private NAT).
    • Architecting hybrid DNS topology: Define forwarding paths, inbound policies, cross-project binding, and DNS peering strategy.
    • Determining the correct MTU sizing for hybrid connections (Cloud Interconnect and HA VPN) for workloads.
    • Understanding interconnect encryption options, such as MACsec and HA VPN, over Cloud Interconnect.
  4. 1.4Designing for Google Kubernetes Engine (GKE)
    • Choosing between public or private cluster nodes and node pools.
    • Choosing between public or private control plane endpoints.
    • Planning subnets: Primary and secondary ranges.
    • Planning for GKE IP addresses using (RFC 1918, non-RFC 1918, Google-managed services range, PSC, shared IP ranges, and PUPI).
    • Planning for IPv6.
    • Designing load balancing for GKE networking.
    • Adding and managing node pool configuration.

Outline reproduced from the vendor's public exam guide for study reference.Official guide

PCNE practice — frequently asked questions

Are these real PCNE exam questions?

No. Every question on CertifyCloudx is original, written by us against Google Cloud's publicly available PCNE exam guide to rehearse the skills it lists. None are actual exam questions, and CertifyCloudx is not affiliated with or endorsed by Google Cloud.

How many PCNE practice questions are there?

532 practice questions, including 3 full-length timed mock exams and 54 domain papers of up to 25 questions (mixed and by topic). Every question has a detailed explanation of why the right answer wins and why each distractor loses.

Is the content up to date with the current PCNE exam guide?

The questions are written against the PCNE exam guide dated 2026-09-14, and we revise them when Google Cloud updates the guide.

What question formats are covered?

The same formats the real PCNE uses: Multiple choice, Multiple response. Each is rendered and graded the way the exam does it.

How long is the PCNE exam and how many questions does it have?

According to Google Cloud's published exam details: 50–60 questions, 120 minutes, passing score Pass / Fail (undisclosed). Our mock exams use the same time limit, with a question count in the middle of that range. Always confirm current details with Google Cloud before booking.

Can I practise PCNE for free?

Yes. 3 papers are free, with up to 10 questions a day on the free plan and no card needed. Pro unlocks every paper and mock exam with no daily limit.

Does CertifyCloudx guarantee that I will pass?

No practice material can guarantee a result. CertifyCloudx helps you find and close your weak areas — accuracy by exam-guide domain and topic shows what to study next.