Skip to content

GCP Professional Cloud Network Engineer - Comprehensive Fact Sheet

Table of Contents


Exam Overview

πŸ“– Professional Cloud Network Engineer Certification - Official certification page with exam guide and sample questions

πŸ“– Exam Guide PDF - Detailed exam domains and objectives breakdown

Exam Details: - Duration: 2 hours - Questions: 50-60 (multiple choice and multiple select) - Cost: $200 USD - Validity: 2 years - Languages: English, Japanese - Format: Remote or test center

Exam Domains: 1. Designing, planning, and prototyping a GCP network (26%) 2. Implementing Virtual Private Cloud (VPC) instances (21%) 3. Configuring network services (23%) 4. Implementing hybrid interconnectivity (14%) 5. Implementing network security (16%)


Virtual Private Cloud (VPC)

VPC Fundamentals

πŸ“– VPC Overview - Comprehensive introduction to Virtual Private Cloud networking in GCP

πŸ“– VPC Networks - Detailed documentation on VPC network creation and management

πŸ“– Subnets - Understanding subnet creation, modification, and regional characteristics

πŸ“– Auto Mode vs Custom Mode VPC - Comparison of automatic and custom subnet creation modes

πŸ“– VPC Network Architecture Best Practices - Design patterns and recommendations for production VPC networks

πŸ“– Expanding Subnet IP Ranges - How to expand existing subnet CIDR ranges without disruption

πŸ“– Creating VPC Networks - Step-by-step guide for creating and configuring VPC networks

πŸ“– Alias IP Ranges - Configuring multiple internal IP addresses on VM network interfaces

πŸ“– Multiple Network Interfaces - Attaching VMs to multiple VPC networks simultaneously

Firewall Rules

πŸ“– VPC Firewall Rules Overview - Understanding stateful firewall rule implementation in GCP

πŸ“– Firewall Rules Components - Direction, priority, action, target, source/destination filters

πŸ“– Hierarchical Firewall Policies - Organization and folder-level firewall policy management

πŸ“– Firewall Rules Logging - Enabling and analyzing firewall rule logs for security auditing

πŸ“– Firewall Insights - Analyzing firewall rule usage and optimizing configurations

πŸ“– Network Tags - Using tags to apply firewall rules to specific VM instances

πŸ“– Service Accounts in Firewall Rules - Identity-based firewall targeting using service accounts

πŸ“– Implied and Pre-populated Rules - Understanding default deny and allow rules in VPC networks

Routes

πŸ“– Routes Overview - How GCP routes traffic between subnets and external destinations

πŸ“– Static Routes - Creating custom static routes for specific traffic patterns

πŸ“– Dynamic Routes - Routes learned through Cloud Router and BGP peering

πŸ“– Route Priority - Understanding route selection based on specificity and priority

πŸ“– Next Hop Types - Instance, IP address, VPN tunnel, and internet gateway next hops


Shared VPC & VPC Peering

Shared VPC

πŸ“– Shared VPC Overview - Connecting resources from multiple projects to a common VPC network

πŸ“– Shared VPC Architecture - Design patterns for enterprise multi-project networking

πŸ“– Setting up Shared VPC - Step-by-step configuration of host and service projects

πŸ“– Shared VPC IAM Roles - Required permissions for host and service project administrators

πŸ“– Shared VPC with GKE - Running Kubernetes clusters in Shared VPC environments

πŸ“– Service Project Admin Best Practices - Delegating network administration in service projects

VPC Network Peering

πŸ“– VPC Network Peering Overview - Connecting VPC networks across projects or organizations privately

πŸ“– VPC Peering Configuration - Creating and managing peering connections between networks

πŸ“– Peering Subnet Routes - Understanding automatic subnet route exchange in peered networks

πŸ“– Peering Custom Routes - Importing and exporting custom routes across peering connections

πŸ“– VPC Peering Limitations - Transitive peering restrictions and overlapping IP constraints

πŸ“– Peering vs Shared VPC - Choosing the right multi-project networking approach


Hybrid Connectivity

Cloud VPN

πŸ“– Cloud VPN Overview - Securely connecting on-premises networks to GCP via IPsec tunnels

πŸ“– HA VPN - High availability VPN with 99.99% SLA and redundant tunnels

πŸ“– Classic VPN - Legacy single-tunnel VPN solution (deprecated for new deployments)

πŸ“– Creating HA VPN Gateways - Step-by-step HA VPN deployment with redundancy

πŸ“– VPN Supported IKE Ciphers - Supported encryption algorithms and IKE versions

πŸ“– VPN Topologies - Common VPN deployment patterns and architectures

πŸ“– VPN with Dynamic Routing - Configuring BGP over VPN tunnels via Cloud Router

πŸ“– VPN Monitoring and Logs - Monitoring VPN tunnel status and troubleshooting connectivity

Cloud Interconnect

πŸ“– Cloud Interconnect Overview - Dedicated private connectivity between on-premises and GCP

πŸ“– Dedicated Interconnect - Physical connections at Google colocation facilities (10 Gbps or 100 Gbps)

πŸ“– Partner Interconnect - Connectivity through supported service providers (50 Mbps to 50 Gbps)

πŸ“– Choosing Interconnect Options - Decision tree for selecting VPN, Dedicated, or Partner Interconnect

πŸ“– VLAN Attachments - Configuring Layer 2 connections over Interconnect circuits

πŸ“– Interconnect Pricing - Understanding attachment, egress, and port costs

πŸ“– Interconnect Colocation Facilities - Finding available Google colocation points globally

πŸ“– Interconnect SLA - Service level agreements for Interconnect availability

πŸ“– Setting up Dedicated Interconnect - Complete deployment guide for dedicated connections

πŸ“– Setting up Partner Interconnect - Provisioning partner-based connectivity

Cloud Router

πŸ“– Cloud Router Overview - Managed BGP routing for dynamic route exchange with on-premises

πŸ“– Cloud Router Configuration - Setting up BGP sessions and route advertisements

πŸ“– BGP Route Advertisement - Controlling which routes are advertised to on-premises

πŸ“– Custom Route Advertisement - Selectively advertising specific IP ranges via BGP

πŸ“– Viewing Learned Routes - Monitoring routes learned from on-premises networks

πŸ“– BFD for Cloud Router - Bidirectional Forwarding Detection for fast failover

Private Google Access

πŸ“– Private Google Access Overview - Accessing Google APIs from VMs without external IP addresses

πŸ“– Configuring Private Google Access - Enabling subnet-level private access to Google services

πŸ“– Private Google Access for On-Premises - Accessing Google APIs from on-premises networks via VPN/Interconnect

πŸ“– Private Service Connect - Consuming Google-managed or third-party services using internal IPs

πŸ“– Private Service Connect for Google APIs - Accessing Google APIs through VPC endpoints


Load Balancing

Load Balancing Overview

πŸ“– Cloud Load Balancing Overview - Introduction to GCP's global and regional load balancing portfolio

πŸ“– Choosing a Load Balancer - Decision matrix for selecting the right load balancer type

πŸ“– External vs Internal Load Balancing - Understanding external internet-facing and internal private load balancers

Application Load Balancer (HTTP/S)

πŸ“– Application Load Balancer - Global HTTP(S) Layer 7 load balancing with content-based routing

πŸ“– URL Maps - Defining traffic routing rules based on URL paths and hosts

πŸ“– Backend Services - Configuring backend instance groups, NEGs, and health checks

πŸ“– Backend Buckets - Serving static content from Cloud Storage via load balancer

πŸ“– SSL Certificates - Managing SSL/TLS certificates for HTTPS load balancing

πŸ“– SSL Policies - Configuring TLS versions and cipher suites for security compliance

πŸ“– Cloud Armor Integration - Enabling DDoS protection and WAF rules on HTTP(S) load balancers

πŸ“– Identity-Aware Proxy (IAP) with Load Balancing - Adding identity-based access control to load-balanced applications

Network Load Balancer

πŸ“– Network Load Balancer Overview - Regional Layer 4 TCP/UDP pass-through load balancing

πŸ“– External Network Load Balancer - Regional external TCP/UDP load balancing configurations

πŸ“– Internal Network Load Balancer - Private internal TCP/UDP load balancing within VPC

πŸ“– Session Affinity - Configuring client IP, cookie, or header-based session persistence

Proxy Network Load Balancer

πŸ“– Proxy Network Load Balancer - Global TCP/SSL proxy load balancing for non-HTTP traffic

πŸ“– SSL Proxy Load Balancer - Global SSL/TLS termination for encrypted non-HTTP protocols

πŸ“– TCP Proxy Load Balancer - Global TCP proxy for worldwide application access

Advanced Load Balancing Features

πŸ“– Health Checks - Configuring automated backend health monitoring and failure detection

πŸ“– Health Check Intervals - Understanding check frequency, timeout, and threshold settings

πŸ“– Traffic Distribution Algorithms - Round robin, weighted, and connection-based distribution modes

πŸ“– Connection Draining - Gracefully removing backends from service without dropping connections

πŸ“– Custom Request Headers - Adding or modifying HTTP headers at the load balancer

πŸ“– Outlier Detection - Automatically removing unhealthy backends based on error rates


Network Services

Cloud CDN

πŸ“– Cloud CDN Overview - Global content delivery network for accelerating application content

πŸ“– Enabling Cloud CDN - Configuring CDN with Cloud Storage backends

πŸ“– Cache Modes - CACHE_ALL_STATIC, USE_ORIGIN_HEADERS, and FORCE_CACHE_ALL modes

πŸ“– Cache Keys - Customizing cache keys based on host, protocol, query string

πŸ“– Signed URLs and Signed Cookies - Controlling access to cached content with time-limited tokens

πŸ“– Cache Invalidation - Purging cached content before TTL expiration

πŸ“– Negative Caching - Caching error responses to reduce origin load

πŸ“– Media CDN - Next-generation CDN optimized for media and large files

Cloud NAT

πŸ“– Cloud NAT Overview - Managed network address translation for outbound internet access

πŸ“– Cloud NAT Architecture - Understanding NAT gateway implementation and scaling

πŸ“– Setting up Cloud NAT - Creating NAT gateways for specific regions and subnets

πŸ“– NAT IP Addresses - Automatic and manual NAT IP address allocation

πŸ“– Port Allocation - Understanding port allocation limits and scaling

πŸ“– NAT Logging - Enabling logs for NAT translation events and troubleshooting

Cloud DNS

πŸ“– Cloud DNS Overview - Scalable, reliable managed DNS hosting service

πŸ“– Managed Zones - Creating public and private DNS zones

πŸ“– Private DNS Zones - Internal DNS resolution for VPC resources

πŸ“– DNS Peering - Sharing DNS configuration across VPC networks

πŸ“– Split-Horizon DNS - Different responses for internal vs external queries

πŸ“– DNSSEC - Enabling DNS Security Extensions for zone signing

πŸ“– Cloud DNS Policies - Creating inbound and outbound server policies for hybrid DNS


Network Security

Cloud Armor

πŸ“– Cloud Armor Overview - DDoS protection and Web Application Firewall for HTTP(S) load balancers

πŸ“– Security Policies - Creating and managing Cloud Armor security rules

πŸ“– Preconfigured WAF Rules - OWASP Top 10 protection, SQL injection, and XSS mitigation

πŸ“– Custom Rules with CEL - Writing custom security rules using Common Expression Language

πŸ“– Rate Limiting - Throttling excessive requests per client IP

πŸ“– Adaptive Protection - Machine learning-based DDoS attack detection and mitigation

πŸ“– Bot Management - Identifying and blocking malicious bot traffic

πŸ“– Preview Mode - Testing security rules without enforcing blocks

Identity-Aware Proxy

πŸ“– Identity-Aware Proxy Overview - Centralized authentication and authorization for applications

πŸ“– Enabling IAP - Setting up IAP for Compute Engine, GKE, and App Engine

πŸ“– IAP Policies - Controlling access with IAM roles and conditions

πŸ“– IAP TCP Forwarding - Secure SSH and RDP access without bastion hosts

πŸ“– Context-Aware Access - Enforcing access policies based on device and network attributes

VPC Service Controls

πŸ“– VPC Service Controls Overview - Creating security perimeters around Google Cloud resources

πŸ“– Service Perimeters - Defining resource boundaries to prevent data exfiltration

πŸ“– Access Levels - Defining contextual access criteria for perimeter bridges

πŸ“– Supported Services - List of GCP services that can be protected by perimeters

πŸ“– Dry Run Mode - Testing perimeter policies without enforcement

SSL/TLS Security

πŸ“– Certificate Manager - Centralized SSL/TLS certificate provisioning and management

πŸ“– Google-Managed SSL Certificates - Automated certificate provisioning and renewal

πŸ“– Self-Managed SSL Certificates - Uploading custom certificates to GCP

πŸ“– mTLS Authentication - Mutual TLS authentication for client certificate validation

Packet Mirroring

πŸ“– Packet Mirroring Overview - Cloning network traffic for security analysis and monitoring

πŸ“– Setting up Packet Mirroring - Configuring mirroring policies and collectors

πŸ“– Mirroring Filters - Selective traffic capture based on source, destination, and protocol


Network Monitoring & Troubleshooting

Network Intelligence Center

πŸ“– Network Intelligence Center Overview - Comprehensive network monitoring and troubleshooting platform

πŸ“– Network Topology - Visualizing VPC network architecture and connectivity

πŸ“– Connectivity Tests - Testing reachability between endpoints and diagnosing issues

πŸ“– Performance Dashboard - Monitoring packet loss, latency, and throughput metrics

πŸ“– Firewall Insights - Analyzing firewall rule usage and identifying misconfigurations

Flow Logs

πŸ“– VPC Flow Logs Overview - Network traffic sampling for analysis, auditing, and forensics

πŸ“– Enabling Flow Logs - Configuring flow log sampling and aggregation intervals

πŸ“– Flow Logs Metadata - Understanding logged fields and information available

πŸ“– Analyzing Flow Logs - Querying logs in Cloud Logging and BigQuery

Cloud Monitoring

πŸ“– Monitoring Network Metrics - Available network metrics for VPC, load balancers, and VPN

πŸ“– Network Alerting - Creating alerts for network anomalies and threshold violations

πŸ“– Custom Dashboards - Building network monitoring dashboards with Cloud Monitoring

Troubleshooting Tools

πŸ“– Troubleshooting VPC Connectivity - Common connectivity issues and resolution steps

πŸ“– Testing VPN Connectivity - Diagnosing VPN tunnel and routing problems

πŸ“– Load Balancer Troubleshooting - Common load balancer issues and debugging techniques

πŸ“– DNS Troubleshooting - Resolving Cloud DNS configuration and resolution issues


IP Addressing & DNS

IP Address Management

πŸ“– IP Addresses Overview - Internal, external, ephemeral, and static IP addressing

πŸ“– Reserving Static IP Addresses - Creating persistent external IP addresses

πŸ“– Internal IP Address Reservation - Reserving specific internal IPs within subnets

πŸ“– Bring Your Own IP (BYOIP) - Importing your own public IP address ranges to GCP

πŸ“– IP Address Pricing - Understanding costs for static and ephemeral IP addresses

IPv6 Support

πŸ“– IPv6 in VPC - Enabling dual-stack IPv4/IPv6 networking

πŸ“– IPv6 Subnet Ranges - Configuring IPv6 CIDR blocks for subnets

πŸ“– IPv6 External Addresses - Assigning IPv6 addresses to VM instances


Advanced Networking

Network Endpoint Groups (NEGs)

πŸ“– Network Endpoint Groups Overview - Logical groupings of backend endpoints for load balancers

πŸ“– Zonal NEGs - IP:port endpoint groups within specific zones

πŸ“– Internet NEGs - Routing traffic to endpoints outside GCP

πŸ“– Serverless NEGs - Load balancing to Cloud Run, App Engine, and Cloud Functions

πŸ“– Hybrid Connectivity NEGs - Routing to on-premises endpoints via VPN/Interconnect

Traffic Director

πŸ“– Traffic Director Overview - Service mesh traffic management for microservices

πŸ“– Traffic Director Architecture - Control plane for Envoy-based service proxies

πŸ“– Traffic Splitting - Weighted routing and canary deployments

Network Service Tiers

πŸ“– Network Service Tiers Overview - Premium vs Standard tier network routing

πŸ“– Premium Tier - Google's global network for lowest latency and highest reliability

πŸ“– Standard Tier - Regional internet routing for cost optimization

πŸ“– Choosing Network Tiers - Performance vs cost trade-offs

Private Google Access Variants

πŸ“– Private Google Access Variants - Different methods for accessing Google APIs privately

πŸ“– Private Google Access for Services - VPC-native access to Google services

πŸ“– Serverless VPC Access - Connecting Cloud Run and Cloud Functions to VPC networks

Advanced Security Features

πŸ“– Binary Authorization for Borg - Container deployment security policies

πŸ“– Organization Policy Constraints - Network configuration guardrails at organization level

πŸ“– VPC Flow Logs to BigQuery - Long-term retention and analysis of network flows


Exam Preparation Resources

Official Google Resources

πŸ“– Google Cloud Skills Boost - Official hands-on labs and learning paths

πŸ“– Network Engineer Learning Path - Curated courses and labs for certification preparation

πŸ“– Google Cloud Documentation - Comprehensive product documentation

πŸ“– Google Cloud Blog - Networking - Latest networking features and best practices

πŸ“– Google Cloud Architecture Center - Reference architectures and design patterns

Practice and Labs

πŸ“– Qwiklabs - Networking Quests - Hands-on networking labs

πŸ“– GCP Free Tier - Always free resources for practice environments

πŸ“– Coursera - Networking in Google Cloud - Official training courses


Quick Reference Commands

gcloud Network Commands

# VPC and Subnet Management
gcloud compute networks create NETWORK_NAME --subnet-mode=custom
gcloud compute networks subnets create SUBNET_NAME --network=NETWORK_NAME --region=REGION --range=CIDR

# Firewall Rules
gcloud compute firewall-rules create RULE_NAME --network=NETWORK_NAME --allow=tcp:80,tcp:443
gcloud compute firewall-rules list --filter="network:NETWORK_NAME"

# VPC Peering
gcloud compute networks peerings create PEERING_NAME --network=NETWORK_NAME --peer-network=PEER_NETWORK

# Cloud Router
gcloud compute routers create ROUTER_NAME --network=NETWORK_NAME --region=REGION --asn=ASN
gcloud compute routers add-bgp-peer ROUTER_NAME --peer-name=PEER_NAME --peer-asn=PEER_ASN

# Cloud NAT
gcloud compute routers nats create NAT_NAME --router=ROUTER_NAME --auto-allocate-nat-external-ips

# Load Balancer Backend Services
gcloud compute backend-services create BACKEND_NAME --protocol=HTTP --health-checks=HEALTH_CHECK

# Cloud VPN
gcloud compute vpn-gateways create VPN_GATEWAY_NAME --network=NETWORK_NAME --region=REGION

# Interconnect
gcloud compute interconnects attachments create ATTACHMENT_NAME --router=ROUTER_NAME --region=REGION

# Cloud DNS
gcloud dns managed-zones create ZONE_NAME --dns-name=example.com --description="My DNS zone"
gcloud dns record-sets create www.example.com --zone=ZONE_NAME --type=A --ttl=300 --rrdatas=1.2.3.4

# Network Intelligence
gcloud network-management connectivity-tests create TEST_NAME --source-instance=SOURCE --destination-ip=DEST_IP

Key Networking Concepts

Network Latency & Performance

Latency Optimization: - Use Premium Network Tier for global applications - Deploy resources in multiple regions close to users - Enable Cloud CDN for static content - Use HTTP/2 and connection multiplexing - Optimize backend response times

Bandwidth Optimization: - Right-size interconnect connections - Use compression for HTTP traffic - Implement efficient caching strategies - Monitor and optimize egress costs - Use internal IPs for intra-region traffic

High Availability Patterns

Multi-Zone Deployments: - Distribute instances across zones - Use regional managed instance groups - Configure health checks appropriately - Implement graceful connection draining - Test failover scenarios regularly

Multi-Region Architectures: - Global load balancing for traffic distribution - Regional backend services for isolation - Cross-region VPN or Interconnect - DNS-based failover strategies - Data replication considerations

Cost Optimization

Network Cost Reduction: - Use internal IPs for intra-region communication - Minimize egress to internet - Choose appropriate network tier (Premium vs Standard) - Right-size interconnect bandwidth - Optimize NAT IP allocation

Load Balancer Cost Optimization: - Consolidate forwarding rules where possible - Use instance groups instead of instance targets - Implement efficient health check intervals - Consider regional vs global load balancing needs


Exam Tips & Strategies

Domain-Specific Focus

VPC Design (26% of exam): - Master subnet sizing and CIDR planning - Understand Shared VPC vs VPC Peering use cases - Know firewall rule evaluation order - Practice routing and next-hop scenarios

VPC Implementation (21% of exam): - Hands-on practice creating VPCs and subnets - Configure firewall rules with various targets - Set up private Google access - Implement alias IP ranges

Network Services (23% of exam): - Know all load balancer types and use cases - Understand Cloud CDN cache modes - Practice SSL certificate management - Configure Cloud NAT and Cloud DNS

Hybrid Connectivity (14% of exam): - Compare VPN, Dedicated Interconnect, Partner Interconnect - Understand Cloud Router and BGP configuration - Know redundancy and failover patterns - Practice VPN troubleshooting

Network Security (16% of exam): - Master Cloud Armor rule configuration - Understand IAP and context-aware access - Know VPC Service Controls concepts - Practice packet mirroring setup

Common Exam Scenarios

Scenario-Based Questions: - Choose appropriate connectivity option (cost, latency, bandwidth) - Design multi-region network architecture - Troubleshoot connectivity issues - Optimize for performance or cost - Implement security requirements

Best Practices Questions: - Recommended firewall rule patterns - Load balancer selection criteria - HA/DR architecture patterns - Security hardening techniques - Monitoring and alerting strategies


Certification Value

Career Impact

Job Roles: - Cloud Network Engineer: $110,000 - $160,000 - Senior Network Architect: $130,000 - $200,000 - Cloud Infrastructure Engineer: $120,000 - $180,000 - Network Security Engineer: $115,000 - $175,000 - Solutions Architect (Networking): $125,000 - $190,000

Skills Validated: - Enterprise network design and implementation - Hybrid cloud connectivity expertise - Network security and compliance - Performance optimization and troubleshooting - Google Cloud platform expertise

Professional Development

Complementary Certifications: - Professional Cloud Architect - Professional Cloud Security Engineer - Cisco CCNP/CCIE Enterprise - CompTIA Network+ - AWS Certified Advanced Networking

Continuing Education: - Stay current with GCP networking announcements - Practice with new features in test environments - Participate in Google Cloud communities - Attend Google Cloud Next conference - Contribute to networking forums and discussions


Additional Resources

πŸ“– GCP Network Engineer Exam Guide - Official detailed exam topics

πŸ“– Google Cloud Networking Deep Dive - Technical blog posts and tutorials

πŸ“– Network Reliability Engineering - Google's approach to network reliability

πŸ“– Cloud OnBoard: Networking - Free virtual training sessions


This fact sheet contains 100 embedded documentation links to official Google Cloud documentation.

Last Updated: October 2024 Certification Validity: 2 years from passing Recertification: Required every 2 years