Professional Cloud Network Engineer Exam Prep
Free practice questions

Free PCNE Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The PCNE exam has 60 questions and runs 2 hours.

These 10 free PCNE questions are organized by exam domain, so you can see how each part of the Professional Cloud Network Engineer blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Designing and planning a Google Cloud VPC network 21% of exam

Question 1

A software vendor runs a TCP service behind an internal passthrough Network Load Balancer. Customers remain in their own Google Cloud organizations, and several customer VPCs overlap the vendor's address ranges. Customers must reach only this service through internal IP addresses, without renumbering either side or exchanging subnet routes. Which connection model fits?

Show answer & explanation

Correct answer: C - Publish a Private Service Connect service attachment and let customers create endpoints in their VPCs.

Question 2

An IP allocation review for a new VPC-native GKE Standard cluster specifies a maximum of 52 Pods per node, including system Pods. The cluster must accommodate 28 regular nodes plus six additional nodes during upgrades, all using one dedicated Pod secondary IPv4 range. Node and Service address space is sufficient. The approved maximum-Pods setting cannot be reduced. Which is the smallest Pod range that supports the plan?

Show answer & explanation

Correct answer: C - 10.60.0.0/19

Question 3

A global retailer runs the same HTTPS application in us-central1 and europe-west1. Each region can carry the full production load. Clients must use one stable public IPv4 address, and new requests must continue after either region fails without waiting for a DNS change. The frontend must also route /catalog and /checkout to different backend services. Which design should be deployed?

Show answer & explanation

Correct answer: A - A Premium Tier global external Application Load Balancer with healthy backends in both regions.

Domain 2: Implementing a VPC network 20% of exam

Question 4

A nightly export from a VM in service perimeter 'analytics' must write to a Cloud Storage bucket in service perimeter 'archive'. IAM grants are correct, and analytics already permits the exact outbound identity, operation, and destination. The request is rejected with a VPC Service Controls ingress violation at archive. The two perimeters must remain separate. What is the narrowest corrective action?

Show answer & explanation

Correct answer: B - Add an archive ingress rule limited to the export identity, source project, destination project, and required Cloud Storage operation.

Question 5

In a GKE Dataplane V2 cluster, payments Pods can resolve ledger's Service name but cannot connect to ledger on TCP 8443. The only egress policy selecting payments allows UDP and TCP port 53 to the DNS resolver. Ledger's ingress policy already allows payments Pods on TCP 8443. Routing and VPC firewall rules permit the traffic, and ledger is listening. Which policy change restores this connection without opening unrelated traffic?

Show answer & explanation

Correct answer: D - Add payments egress permission to ledger Pods on TCP 8443.

Domain 3: Configuring managed network services 16% of exam

Question 6

Cloud DNS forwards corp.example queries to an on-premises resolver at 172.20.10.53 across HA VPN. A VM in 10.40.0.0/16 resolves the name when querying 172.20.10.53 directly, but queries through the VM's Google-provided resolver fail. An on-premises capture shows a forwarded query arriving from 35.199.196.20 and the DNS server sending a reply. The on-premises routing table sends only 10.40.0.0/16 through the VPN. What should be changed to complete the forwarding path?

Show answer & explanation

Correct answer: D - Advertise 35.199.192.0/19 to the on-premises router through the VPN's Cloud Router.

Question 7

A travel site serves public fare displays at /fares?currency=USD and /fares?currency=EUR. Direct origin requests return the correct currency, but Cloud CDN sometimes returns the currency requested by the previous visitor. The backend service's cache key excludes query parameters. Responses contain no user-specific data, and caching must remain enabled. Which change prevents the mix-up?

Show answer & explanation

Correct answer: B - Include the currency query parameter in the backend service's cache key.

Domain 4: Configuring and implementing hybrid and multicloud network interconnectivity 16% of exam

Question 8

A design review finds that an existing Dedicated Interconnect connection uses MACsec. A new security requirement calls for IPsec protection between the company's on-premises VPN appliance and Google Cloud's VPN gateway, with encrypted traffic remaining on the private Interconnect path. Which architecture satisfies the requirement?

Show answer & explanation

Correct answer: A - Create encrypted VLAN attachments and establish HA VPN tunnels over the Interconnect connections.

Domain 5: Managing, monitoring, and troubleshooting network operations 14% of exam

Question 9

During a load test, a Public NAT gateway uses static allocation of 1,024 ports per VM. Most VMs stay below 100 connections to any one destination; a few gradually ramp toward 1,800 concurrent connections to the same vendor IP and TCP port. Their port-usage metric approaches 1,024, and OUT_OF_RESOURCES drops increase. The NAT address pool has spare capacity, and endpoint-independent mapping is disabled. Which allocation change accommodates these bursts without reserving peak capacity for every VM?

Show answer & explanation

Correct answer: A - Use dynamic allocation with a minimum of 1,024 and a maximum of 4,096 ports per VM.

Domain 6: Configuring, implementing and managing a cloud network security solution 13% of exam

Question 10

At 09:20, a checkout service begins receiving confirmed SQL-injection attempts from rapidly changing source addresses. All requests pass through a global external Application Load Balancer. Its backend Cloud Armor policy has a tuned SQL-injection deny rule in preview mode ahead of the broad allow rule. Preview logs show matches for the attack traffic, and replay tests confirm that legitimate checkout requests do not match. The application patch is not ready. Which immediate action contains the attack with the least customer disruption?

Show answer & explanation

Correct answer: B - Enforce the validated SQL-injection rule by turning off preview mode.

That's 10 of 1,030

The full bank has 1,020 more PCNE questions with explanations.

Continue in the free practice test →

View plans