PCNE sample questions with answers

10 free practice questions for the Professional Cloud Network Engineer exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Designing and planning a Google Cloud VPC network

Following an acquisition, Sandrine Foods must connect a manufacturer whose data centres consume almost all of 10.0.0.0/8, including ranges already used by Sandrine's production VPC. Re-addressing either estate is impossible because of embedded shop-floor controllers. New Google Cloud subnets are needed for the acquired workloads, which must initiate connections to a shared inventory service in Sandrine's existing VPC. What should you do?

  1. A.

    Allocate the new subnets from the RFC 6598 range 100.64.0.0/10, which Google Cloud supports as a privately used non-RFC 1918 subnet range, and peer that VPC with Sandrine's production VPC.

  2. B.

    Re-address the acquired company's shop-floor networks into 172.16.0.0/12 before the first migration wave.

  3. C.

    Create a VPC Network Peering connection between the two networks and enable the option to allow overlapping subnet ranges.

  4. D.

    Assign external IPv6 addresses to the migrated workloads and reach the inventory service through an external Application Load Balancer over the public internet, restricted by a Google Cloud Armor allowlist.

Show answer

Answer: A

Google Cloud subnets accept non-RFC 1918 ranges, so carving the new subnets from 100.64.0.0/10 avoids the collision entirely and lets the two VPCs peer.

  • A. Google Cloud VPC subnets accept non-RFC 1918 ranges such as 100.64.0.0/10, giving the migrated workloads address space that collides with neither estate and peers cleanly.
  • B. Re-addressing the shop-floor networks is exactly the project the business ruled out because of the embedded controllers.
  • C. VPC Network Peering explicitly refuses to establish when subnet ranges overlap and offers no setting to permit the overlap.
  • D. Fronting an internal inventory service with an internet-facing load balancer adds public exposure and latency when private, non-overlapping connectivity is available.
Question 2Designing and planning a Google Cloud VPC network

Marlowe Digital is planning a VPC-native GKE cluster in europe-west2 that must grow to 400 nodes. The platform team will keep the default maximum of 110 Pods per node, so GKE allocates a /24 of Pod address space to each node, and the application catalogue requires about 1,800 Kubernetes Services. The cluster must reach the full node count without a rebuild. Which subnet and secondary range sizes should you specify?

  1. A.

    Primary range /22 for nodes, Pod secondary range /15, Service secondary range /28.

  2. B.

    Primary range /22 for nodes, Pod secondary range /17, Service secondary range /21.

  3. C.

    Primary range /22 for nodes, Pod secondary range /15, Service secondary range /21.

  4. D.

    A single primary range /16 for nodes, Pods and Services, using a routes-based cluster.

Show answer

Answer: C

At 110 Pods per node each node consumes a /24, so 400 nodes need a /15 Pod range, 1,800 Services need a /21, and 400 node addresses fit a /22.

  • A. A /28 Service range provides only 16 addresses, which cannot accommodate the 1,800 Services the catalogue requires.
  • B. A /17 Pod range provides only 128 per-node /24 blocks, so the cluster would stop scaling at roughly 128 nodes, far short of 400.
  • C. A /15 Pod range yields 512 per-node /24 blocks for 400 nodes, a /21 covers 1,800 Services, and a /22 primary range holds 400 node addresses with headroom.
  • D. Routes-based clusters are the legacy model, consume VPC route quota per node, and do not use the secondary ranges the question asks you to size.
Question 3Designing and planning a Google Cloud VPC network

Kirkmoor Bank must inspect every packet leaving the application subnet 10.30.0.0/20 in europe-west3 before it reaches on-premises networks. The security vendor supplies a multi-NIC next-generation firewall image that the bank will run as two instances in different zones. Audit requires that a single appliance failure must not black-hole traffic, and that established TCP sessions must not be redistributed to the surviving appliance mid-flow while the failed appliance drains. What should you do?

  1. A.

    Create two custom static routes for the on-premises destinations with equal priority, one with next-hop-instance pointing at each appliance, so traffic is shared by equal-cost multi-path.

  2. B.

    Create a policy-based route that sends the subnet's traffic to a global external Application Load Balancer fronting the two appliances.

  3. C.

    Put the appliance instances in a managed instance group behind an internal passthrough Network Load Balancer, and create a custom static route for the on-premises destinations whose next hop is that load balancer's forwarding rule.

  4. D.

    Create a custom static route for the on-premises destinations with next-hop-instance pointing at the appliance in the primary zone, and a second route with a higher priority value pointing at the standby appliance.

Show answer

Answer: C

An internal passthrough Network Load Balancer used as a route next hop is the supported way to insert a highly available appliance pair without breaking flow symmetry.

  • A. Instance next hops aren't health checked; a route is skipped only when its VM is stopped or deleted, so a hung appliance keeps attracting flows.
  • B. Among load balancers, only an internal passthrough Network Load Balancer can be a route next hop; an external Application Load Balancer cannot be referenced by a route or policy-based route.
  • C. Internal passthrough load balancer as next hop adds health checking and connection tracking, meeting both the no-black-hole and no-rehash requirements.
  • D. The standby route is used only when the primary VM is stopped or deleted; an appliance that hangs while running still black-holes traffic.
Question 4Designing and planning a Google Cloud VPC network

Tessellate Analytics is moving a seismic processing cluster to Compute Engine. The application streams sequential reads from an on-premises parallel file system over a Dedicated Interconnect, and the storage vendor requires 8896-byte frames end to end to hit the throughput target; the on-premises switches and routers already run jumbo frames. A backup HA VPN tunnel over the internet between the same networks must keep working. The VPC has not been created yet. What should you do?

  1. A.

    Create the VPC with the default MTU of 1460, create the VLAN attachments with an MTU of 8896, and enable jumbo frames only on the storage subnet's firewall rules.

  2. B.

    Create the VPC with an MTU of 1500 to match the on-premises LAN and enable large receive offload on the VMs to compensate for the smaller frames.

  3. C.

    Create the VPC with an MTU of 8896, create the VLAN attachments with an MTU of 8896, set the guest OS interface MTU to 8896, and clamp TCP MSS on the HA VPN path.

  4. D.

    Create the VPC with an MTU of 8896 and leave the guest operating systems at their default interface MTU, relying on path MTU discovery to negotiate jumbo frames.

Show answer

Answer: C

Jumbo frames must be set consistently at the VPC, the VLAN attachment and the guest OS, with the lower-MTU VPN path protected by MSS clamping.

  • A. A 1460-byte VPC MTU caps the frames the VMs can send regardless of the attachment setting, and firewall rules have no MTU or frame-size function at all.
  • B. A 1500-byte MTU does not meet the storage vendor's 8896-byte requirement, and receive offload changes host processing, not the frame size on the wire.
  • C. It aligns the VPC, the VLAN attachment and the guest interface at 8896 and handles the lower-MTU VPN path with MSS clamping rather than penalising the primary path.
  • D. Path MTU discovery can only find a smaller MTU along a path; it never raises a guest interface above the MTU the operating system is configured with.
Question 5Designing and planning a Google Cloud VPC network

Ferngate Logistics runs workloads in us-east4 and us-west2 in one VPC network. Its Dedicated Interconnect lands in us-east4, and a second one is being added with VLAN attachments and a Cloud Router in us-west2. On-premises routers honour MED. Traffic for each region's subnets must use that region's attachments in both directions, and fail over to the other region automatically if they fail. What should you do?

  1. A.

    Use global dynamic routing so that each Cloud Router advertises every subnet, adding inter-regional cost to the MED for the other region's subnets.

  2. B.

    Use regional dynamic routing so that each Cloud Router advertises only its own region's subnets, and on-premises uses the other path after a failure.

  3. C.

    Use regional dynamic routing and add custom advertisements for the other region's subnets on each Cloud Router with a higher base priority.

  4. D.

    Use global dynamic routing and set each Cloud Router to custom advertisement listing only its own region's subnets, so that paths stay regional.

Show answer

Answer: A

In global mode, Cloud Routers advertise subnets from other regions with MED equal to base priority plus inter-regional cost, and learned routes are available in every region.

  • A. Global mode gives local-first MEDs toward on-premises and local-first learned routes inside the VPC, with the other region as backup.
  • B. Regional mode never advertises the other region's subnets or installs the other region's learned routes, so there is no failover.
  • C. Advertising remote subnets fixes inbound failover only; in regional mode VMs still lack routes learned in the other region.
  • D. Advertising only local subnets removes the backup path that the requirement calls for.
Question 6Designing and planning a Google Cloud VPC network

Ravenscourt Asset Management's regulator requires that all traffic crossing a third-party carrier be encrypted in transit at the network layer. The estate has two 100-Gbps Dedicated Interconnect connections from a colocation cage where the bank owns the routers, and two 5-Gbps layer 2 Partner Interconnect VLAN attachments serving branch data centres where the carrier owns the path. Throughput and the existing availability commitments must be preserved. Which two actions should you take? (Choose two.)

Choose 2.

  1. A.

    Replace both connection types with Classic VPN tunnels over the public internet using IKEv2.

  2. B.

    Create new Partner Interconnect VLAN attachments with IPsec encryption enabled and run HA VPN over Cloud Interconnect across them for the branch traffic.

  3. C.

    Enable MACsec for Cloud Interconnect on the two 100-Gbps Dedicated Interconnect connections and configure the matching pre-shared keys on the bank's colocation routers.

  4. D.

    Ask the carrier to enable MACsec on its links to Google so that the Partner Interconnect traffic is encrypted across the carrier network.

  5. E.

    Rely on Google's automatic encryption of traffic that transits its production network to satisfy the regulator for both connection types.

Show answer

Answer: B, C

MACsec protects the link between the bank's own router and Google's edge on Dedicated Interconnect, while the carrier-owned Partner paths need HA VPN over Cloud Interconnect for end-to-end IPsec.

  • A. Classic VPN over the internet loses the private path and the Interconnect availability commitments, and each tunnel is limited to about 250,000 packets per second.
  • B. HA VPN over Cloud Interconnect adds end-to-end IPsec across the carrier path; encryption has to be enabled when the VLAN attachments are created.
  • C. MACsec for Cloud Interconnect encrypts the link between the bank's own router and Google's edge router on the Dedicated Interconnect connections.
  • D. MACsec on Partner Interconnect covers only the hop between Google's edge and the provider's edge, not the traffic crossing the carrier's own network.
  • E. Google's automatic encryption covers traffic inside Google's network; it does not protect the carrier segment between the bank and Google's edge.
Question 7Designing and planning a Google Cloud VPC network

Vantablack Studios runs a session-based multiplayer title. Game servers accept UDP on ports 30000-30100 plus a TCP control channel on 7443, and the anti-cheat subsystem hashes the client source IP, so packets must reach the servers with the original client address intact. Players cluster in us-east1, europe-west2 and asia-northeast1. The studio wants one published hostname, automatic removal of an unhealthy region, and the shortest network path per player. What should you do?

  1. A.

    Deploy an internal passthrough Network Load Balancer in each region and expose it to players through Cloud NAT on the same subnet.

  2. B.

    Deploy a global external Application Load Balancer with a URL map that routes players to the closest regional backend service.

  3. C.

    Deploy a regional external passthrough Network Load Balancer in each of the three regions and publish one hostname using a Cloud DNS geolocation routing policy with health checking enabled.

  4. D.

    Deploy a global external proxy Network Load Balancer with a single anycast IP address and add the three health-checked regional instance groups in us-east1, europe-west2 and asia-northeast1 as backends.

Show answer

Answer: C

Only a passthrough Network Load Balancer preserves the client source IP and forwards UDP, so the global behaviour must come from a Cloud DNS geolocation policy with health checks.

  • A. Internal passthrough load balancers only accept traffic originating inside the VPC, and Cloud NAT provides outbound translation, never inbound publishing.
  • B. An Application Load Balancer only accepts HTTP, HTTPS and HTTP/2 traffic, so UDP game traffic on 30000-30100 cannot pass through it at all.
  • C. Passthrough load balancing preserves the client IP and carries UDP, while a health-checked Cloud DNS geolocation policy supplies the single hostname and regional failover.
  • D. A proxy Network Load Balancer only handles TCP and SSL, and it terminates the connection so the game server would see a Google front-end address rather than the player's.
Question 8Designing and planning a Google Cloud VPC network

Aldermere Health runs an internal clinical records application on two GKE clusters, one in europe-west1 and one in europe-west4. Clinicians connect only from hospital networks reached over Dedicated Interconnect, so nothing may be exposed on the internet. The front end needs host and path based routing across four backend services, and if the cluster in either region fails, requests must continue to be served by the other cluster without a DNS change. What should you do?

  1. A.

    Deploy an internal Ingress in each cluster using the gce-internal ingress class and publish both addresses in a Cloud DNS private zone with round-robin records.

  2. B.

    Deploy a global external Application Load Balancer with backends in both clusters and restrict access with a Google Cloud Armor policy that allows only the hospital address ranges.

  3. C.

    Deploy an internal passthrough Network Load Balancer in each cluster and use a Cloud DNS failover routing policy between the two forwarding rule addresses.

  4. D.

    Deploy a multi-cluster Gateway using the cross-region internal managed GatewayClass, with the two clusters registered to a fleet and container-native load balancing to zonal NEGs in each cluster.

Show answer

Answer: D

A multi-cluster Gateway on the cross-region internal managed GatewayClass gives internal-only layer 7 routing with automatic cross-region failover and no DNS change.

  • A. Two independent regional Ingress resources create two addresses, and DNS round robin does not fail over: resolvers keep handing out the dead address.
  • B. A global external Application Load Balancer is internet-facing by definition, which the no-internet-exposure requirement forbids regardless of Cloud Armor filtering.
  • C. Passthrough load balancing works at layer 4 and cannot perform host or path based routing across four backend services.
  • D. The cross-region internal managed GatewayClass with a fleet-registered multi-cluster Gateway gives internal layer 7 routing and automatic cross-region failover.
Question 9Designing and planning a Google Cloud VPC network

Brightmoor Insurance is designing IPv6-only subnets in a VPC network for a new claims workload on Compute Engine. The VMs must call several partner APIs on the internet by host name, and those partners publish only A records and accept only IPv4 connections. The design must not add dual-stack interfaces or proxy VMs. What should you do?

  1. A.

    Create a Cloud DNS response policy that returns an AAAA record for each partner host, pointing at the partner's IPv4 address in hexadecimal.

  2. B.

    Create a Public NAT gateway configured for NAT64 on the IPv6-only subnets, and keep Cloud DNS returning only A records.

  3. C.

    Create a DNS64 server policy on the VPC network, and a Public NAT gateway configured for NAT64 on the IPv6-only subnets.

  4. D.

    Create a DNS64 server policy on the VPC network, and rely on Private Google Access to carry the translated IPv6 traffic to the partners.

Show answer

Answer: C

IPv6-only VMs reach IPv4-only internet services when DNS64 synthesizes AAAA answers in 64:ff9b::/96 and Public NAT performs NAT64 translation.

  • A. Rewriting records by hand provides no translation; the IPv6-only VMs still can't reach an IPv4-only destination.
  • B. Without DNS64, IPv6-only VMs receive only A records, so they have no IPv6 destination to send traffic to the NAT64 gateway.
  • C. DNS64 gives the VMs synthesized IPv6 answers, and NAT64 on Public NAT translates those flows to the partners' IPv4 addresses.
  • D. Private Google Access reaches Google APIs; it doesn't translate IPv6 traffic to third-party IPv4 services on the internet.
Question 10Designing and planning a Google Cloud VPC network

Corbin Media stores its media catalogue in us-east4 and runs a transcoding fleet in another public cloud in the same metropolitan area. The pipeline moves about 60 TB each month and must sustain 10 Gbps during nightly bursts. Security forbids any path over the public internet, and operations wants one provisioning workflow and one support relationship rather than ordering carrier circuits and colocation cross-connects itself. What should you do?

  1. A.

    Build HA VPN tunnels between the Google Cloud HA VPN gateway and the other cloud's VPN gateway over the public internet and use equal-cost multi-path across four tunnels.

  2. B.

    Order a Dedicated Interconnect into a colocation facility, install customer routers, and cross-connect to the other cloud provider's direct connectivity service.

  3. C.

    Use Storage Transfer Service over public endpoints with a service account and rely on TLS to satisfy the security requirement.

  4. D.

    Order a 10-Gbps Cross-Cloud Interconnect connection between Google Cloud and the other cloud provider, create VLAN attachments, and peer a Cloud Router with the remote cloud's gateway over BGP.

Show answer

Answer: D

Cross-Cloud Interconnect is the purpose-built, Google-provisioned private link between a VPC and another cloud provider at 10 or 100 Gbps.

  • A. HA VPN traverses the public internet, which security has forbidden, and per-tunnel throughput cannot sustain the 10 Gbps burst requirement.
  • B. This is the do-it-yourself colocation approach the operations team rejected because it means multiple vendors, cross-connects and support relationships.
  • C. Transferring over public endpoints traverses the internet; TLS encrypts the payload but does not change the network path the policy forbids.
  • D. Cross-Cloud Interconnect is a Google-provisioned private link to another cloud provider at 10 or 100 Gbps with standard VLAN attachments and BGP.

Keep going with 522 more PCNE questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

PCNE sample questions with answers (10 free) · CertifyCloudx