Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GOOGLE CLOUD

Google Cloud Professional Cloud Network Engineer

PROFESSIONAL-CLOUD-NETWORK-ENGINEERProfessional Cloud Network Engineer

The Google Cloud Professional Cloud Network Engineer certification validates your ability to design, implement, and manage secure, scalable network architectures on Google Cloud. It is intended for network engineers who architect hybrid and multi-cloud connectivity, configure network services, and optimize performance and reliability. Earning it demonstrates that you can translate business requirements into robust, production-ready network solutions.

502 practice questions · Updated 2026-07-30

6Domains
22Objectives
195Concepts
502Questions

PROFESSIONAL-CLOUD-NETWORK-ENGINEER Curriculum

Every domain, objective, and concept the PROFESSIONAL-CLOUD-NETWORK-ENGINEER exam measures.

  1. Network Tiers Overview
  2. Selecting Network Tiers
  3. High Availability Design
  4. Failover Strategies
  5. Disaster Recovery Planning
  6. Scaling Network Architecture
  7. DNS Topology Design
  8. Cloud DNS Configuration
  9. On-Premises DNS Integration
  10. Load Balancer Types
  11. Load Balancer Selection Criteria
  12. GKE Networking Fundamentals
  13. Secondary Ranges for GKE
  14. GKE Scale and IP Address Planning
  15. GKE Control Plane Access
  16. IAM Roles for Network Architecture
  17. Shared VPC Subnet Permissions
  18. Private Services Access
  19. Private Service Connect (PSC)
  20. Serverless VPC Access
  21. Quotas and Limits Planning
  22. Monitoring and Adjusting Quotas
  1. VPC Types and Quantity
  2. Network Interconnection Methods
  3. IP Address Management (IPAM) Strategy
  4. Global vs Regional Network Design
  5. MTU Sizing for VPC
  6. Third-Party Device Insertion
  1. Hybrid Connectivity Options
  2. Multicloud Connectivity
  3. Direct Peering vs. Verified Peering Provider
  4. High-Availability and Disaster Recovery Connectivity
  5. Accessing Multiple VPCs from On-Premises
  6. Private Access to Google Services
  7. Private Service Connect and VPC Peering for Managed Services
  8. IP Address Planning and Overlap Avoidance
  9. Hybrid DNS Topology
  10. MTU Sizing for Hybrid Connections
  11. Interconnect Encryption Options
  1. Public vs. Private GKE Cluster Nodes
  2. Public vs. Private Control Plane Endpoints
  3. Primary and Secondary Subnet Ranges for GKE
  4. GKE IP Address Planning with RFC 1918 and Non-RFC 1918
  5. Private Service Connect (PSC) and Shared IP Ranges in GKE
  6. Pod and Service IP Ranges (PUPI) Planning
  7. IPv6 Planning for GKE
  8. Designing Load Balancing for GKE
  9. Node Pool Configuration Management

  1. VPC network creation
  2. Subnet creation and management
  3. Firewall rules and policies
  4. Private services access subnet
  5. Private pools configuration
  6. VPC Network Peering setup
  7. Shared VPC creation
  8. Sharing subnets with service projects
  9. IAM permissions for Shared VPC subnets
  10. Private Google Access configuration
  11. Public interface configuration for Google APIs
  12. Expanding VPC subnet ranges
  13. VPC Service Controls perimeters
  1. Static vs. dynamic routing
  2. Cloud Router and BGP
  3. Global vs. regional dynamic routing
  4. Route creation with network tags
  5. Route priority and precedence
  6. Policy-based routing
  7. Internal load balancer as next hop
  8. Custom route import/export over VPC peering
  9. Custom route import/export over Network Connectivity Center
  1. VPC spoke
  2. Hybrid spoke
  3. Producer spoke
  4. Star topology
  5. Hub and spokes topology
  6. Mesh topology
  7. Private NAT configuration
  8. PSC propagation
  9. IP/CIDR range filters
  10. Monitoring Network Connectivity Center
  11. Troubleshooting Network Connectivity Center
  1. VPC-native clusters and alias IPs
  2. Shared VPC for GKE clusters
  3. Private clusters and private control plane endpoints
  4. Authorized networks for control plane endpoints
  5. DNS-based endpoint for control plane access
  6. GKE Dataplane V2
  7. Source NAT and IP Masquerade policies
  8. GKE network policies
  9. Pod ranges and service ranges
  10. Deploying additional Pod ranges
  11. DNS configuration in GKE

  1. Load balancer type selection
  2. Backend service configuration
  3. Load balancer settings
  4. GKE load balancing
  5. Application Load Balancer traffic management
  1. Cloud CDN overview
  2. Supported origins for Cloud CDN
  3. Setting up Cloud CDN for managed instance groups
  4. Setting up Cloud CDN for Cloud Storage buckets
  5. Setting up Cloud CDN for Cloud Run
  6. Setting up Cloud CDN for internet NEGs
  7. Setting up Cloud CDN for third-party object storage
  8. Invalidating cached content
  9. Cache invalidation best practices
  1. Cloud DNS zone types
  2. Managing DNS records
  3. Migrating DNS to Cloud DNS
  4. Cloud DNS routing policies
  5. Enabling DNSSEC
  6. DNS forwarding and server policies
  7. Split-horizon DNS
  8. Cross-project DNS binding and peering
  9. Cloud DNS with external-dns for GKE

  1. Dedicated Interconnect provisioning
  2. VLAN attachments for Dedicated Interconnect
  3. Partner Interconnect provisioning
  4. Layer 2 vs layer 3 Partner Interconnect
  5. Cross-Cloud Interconnect provisioning
  6. VLAN attachments for Cross-Cloud Interconnect
  7. HA VPN over Cloud Interconnect
  8. Interconnect SLA topologies
  1. HA VPN Overview
  2. HA VPN Configuration Steps
  3. HA VPN to On-Premise Gateways
  4. HA VPN to Other VPCs
  5. Classic VPN Overview
  6. Route-Based Classic VPN
  7. Policy-Based Classic VPN
  8. Troubleshooting VPN Connectivity
  1. BGP attributes
  2. BFD configuration
  3. Custom-advertised routes
  4. Custom-learned routes
  5. Legacy vs standard best path selection
  1. Hybrid Spoke Creation
  2. Site-to-Site Data Transfer
  3. Router Appliance Configuration
  4. Transitivity Issue Resolution

  1. Enable Cloud Logging for networking components
  2. Review Cloud Logging logs for networking components
  3. Monitor networking metrics for Cloud VPN
  4. Monitor networking metrics for Cloud Interconnect and VLAN attachments
  5. Monitor networking metrics for Cloud Router
  6. Monitor networking metrics for load balancers
  7. Monitor networking metrics for Google Cloud Armor
  8. Monitor networking metrics for Cloud NAT
  1. ALB connection draining
  2. ALB traffic redirection
  3. VPN troubleshooting fundamentals
  4. VPN tunnel monitoring and maintenance
  5. Cloud Interconnect troubleshooting
  6. Cloud Interconnect maintenance and monitoring
  7. Cloud Router BGP peering troubleshooting
  8. BGP route and policy verification
  9. VPC Flow Logs for connectivity troubleshooting
  10. Firewall logs for connectivity troubleshooting
  11. Packet Mirroring for deep packet analysis
  1. Network Topology visualization
  2. Connectivity Tests for route and firewall diagnostics
  3. Performance Dashboard analysis
  4. Firewall Insights usage
  5. Network Analyzer for network health
  6. Flow Analyzer and VPC Flow Logs analysis

  1. Edge and backend security policies
  2. WAF rules for common attacks
  3. Advanced network DDoS protection
  4. Rate limiting
  5. Bot management
  6. Google Threat Intelligence integration
  1. Firewall strategy planning
  2. Hierarchical firewall effective policy
  3. Cloud NGFW for GKE and Load Balancing
  4. VPC firewall rule creation and troubleshooting
  5. Cloud NGFW policy management
  6. Layer 7 inspection with Cloud NGFW Enterprise
  7. Migration from VPC firewall rules to Cloud NGFW
  8. Firewall rule criteria configuration
  9. Firewall logging configuration
  10. Micro-segmentation techniques
  11. Cloud NGFW tier differentiation
  1. Cloud NAT IP addressing
  2. Automatic vs manual NAT IP assignment
  3. Cloud NAT port allocation
  4. Static port allocation
  5. Dynamic port allocation
  6. Secure Web Proxy configuration
  7. Secure Web Proxy policies
  8. Integration of Cloud NAT and Secure Web Proxy
  1. Multi-NIC VM Routing for Inter-VPC Traffic
  2. Internal Load Balancer as Next Hop
  3. Policy-Based Routes for HA Multi-NIC VM Routing
  4. Out-of-Band Network Security Integration Strategy
  5. Packet Mirroring Configuration
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for PROFESSIONAL-CLOUD-NETWORK-ENGINEER, so none is invented.