Professional Cloud Network Engineer — 公式シラバス詳細
公式試験ガイド原文を翻訳・整理。サブトピックは原文表現を併記し、項目の取りこぼしを防ぐ。 出典: Exam Guide (PDF, 2024-04-26 改定)
Section 1: Designing and planning a Google Cloud VPC network (~21%)
1.1 全体のネットワーク アーキテクチャ設計 (Designing an overall network architecture)
- ネットワーク階層の違いを理解する: Premium Tier と Standard Tier の違い、Google バックボーン経路 vs Public Internet 経路。
- HA / フェイルオーバー / DR / スケール を見越した設計 (リージョン冗長、グローバル LB)。
- DNS トポロジー設計: オンプレ DNS と Cloud DNS、private/public zone の使い分け。
- 適切なロードバランサーの選択: Application / Network / Proxy / Passthrough × Internal / External × Regional / Global。
- GKE ネットワーキング設計: secondary range、IP アドレス空間のスケール、コントロールプレーンへのアクセス方式。
- IAM ロール選定: ロードバランサーのプロビジョニング、Shared VPC subnet permission など。
- マネージドサービス接続の計画: Private Services Access (PSA)、Private Service Connect (PSC)、Serverless VPC Access。
- クォータと上限の計画。
1.2 VPC ネットワークの設計 (Designing VPC networks)
- VPC の種類と数の選定: スタンドアロン / Shared VPC、VPC 環境数。
- VPC 間の相互接続方式: VPC Network Peering、Network Connectivity Center (mesh/star)、PSC。
- IP アドレス管理戦略 (IPAM): サブネット、IPv6、BYOIP、PUPI (privately used public IP)、Private NAT、非 RFC1918、マネージドサービス、IPAM 自動化。
- グローバル/リージョナル、または両者の組み合わせの設計。
- MTU サイジング: ワークロード要件に応じた VPC MTU (1460 / 1500 / 8896 など)。
- サードパーティ機器の挿入 (NVA) を custom routes (static / policy-based) と LB で実現。
1.3 強靱で高性能なハイブリッド/マルチクラウド ネットワークの設計
- ハイブリッド接続: オンプレ、ブランチ。Dedicated Interconnect / Partner Interconnect / Cloud VPN / SD-WAN。帯域・セキュリティ制約。
- マルチクラウド接続: Cloud VPN、Cross-Cloud Interconnect。
- Direct Peering と Verified Peering Provider の使い分け。
- HA/DR 接続戦略: regional/global dynamic routing mode、複数リージョン冗長。
- オンプレから複数 VPC へのアクセス: Shared VPC / multi-VPC peering / NCC トポロジー。
- Google サービス (Vertex AI, APIs) へのプライベートアクセス。
- マネージドサービスへの接続: PSC、VPC Network Peering 経由の Private Services Access。
- IP アドレス空間設計: 重複回避、Internal ranges、Private NAT。
- ハイブリッド DNS トポロジー: forwarding パス、inbound policy、cross-project binding、DNS peering 戦略。
- ハイブリッド接続の MTU サイジング (Cloud Interconnect, HA VPN)。
- Interconnect 暗号化: MACsec、HA VPN over Cloud Interconnect。
1.4 GKE 向け設計 (Designing for GKE)
- public / private なノード・ノードプールの選択。
- public / private なコントロールプレーンエンドポイントの選択。
- primary / secondary subnet 範囲の計画。
- GKE IP 計画: RFC1918, non-RFC1918, Google-managed services range, PSC, shared IP ranges, PUPI。
- IPv6 対応の計画。
- GKE 向けロードバランシングの設計。
- ノードプールの追加・管理。
Section 2: Implementing a VPC network (~20%)
2.1 VPC の構成
- VPC リソースの作成: network、subnet、firewall rules / policies、Private Services Access subnet、private pools。
- VPC Network Peering 構成。
- Shared VPC の作成と service projects への共有。
- Shared VPC サブネット利用のための IAM 権限割り当て。
- Google API / マネージドサービスへの接続構成: Private Google Access、public interfaces。
- 作成後の VPC サブネット範囲の拡張 (expand)。
- VPC Service Controls perimeter による Google Cloud サービス制限の構成。
2.2 VPC ルーティング
- 静的ルートと動的ルート (Cloud Router) の構成。
- Global / Regional dynamic routing mode の構成。
- network tag と priority によるルーティング。
- Global dynamic routing でのルート優先度: policy-based routing と dynamic routing。
- Internal Load Balancer を next hop に使うルーティング。
- VPC Network Peering / Network Connectivity Center でのカスタムルート import/export。
- Policy-based routing (PBR) の構成。
2.3 Network Connectivity Center (NCC)
- spoke タイプの違い: VPC spoke / hybrid spoke / producer spoke。
- VPC トポロジー管理: star, hub & spokes, mesh。
- Private NAT と PSC propagation の構成。
- NCC spoke の IP/CIDR フィルタ設定。
- NCC の監視・トラブルシュート。
2.4 GKE クラスタの構成・運用
- alias IPs を使った VPC-native cluster の作成。
- Shared VPC でのクラスタ設定。
- private cluster / private control plane endpoint の構成。
- コントロールプレーン用 authorized networks の追加。
- DNS-based endpoint によるコントロールプレーンアクセス。
- GKE Dataplane V2 の有効化。
- SNAT / IP Masquerade ポリシー構成。
- GKE Network Policy の作成。
- Pod range / Service range の構成。
- 追加 Pod range のデプロイ。
- DNS 構成: local DNS cache, Cloud DNS, kube-dns。
Section 3: Configuring managed network services (~16%)
3.1 ロードバランシング
- ネットワークに適した LB ソリューション選定: internal/external × regional/global × application/proxy/passthrough。
- backend services の構成: autoscaling、NEG (Network Endpoint Group)、MIG (Managed Instance Group)。
- balancing method、session affinity、serving capacity、URL maps、health checks、global access の設定。
- GKE 向け LB: Gateway controller / Ingress controller / NEG。
- Application LB の トラフィック管理: splitting / mirroring / URL rewrite。
3.2 Cloud CDN
- サポートオリジンへの設定: MIG、Cloud Storage、Cloud Run。
- 外部バックエンド (internet NEG) や third-party object storage への設定。
- キャッシュ無効化 (invalidation)。
3.3 Cloud DNS
- ゾーン・レコード管理。
- Cloud DNS への移行。
- ルーティングポリシー (geolocation, failover) の構成。
- DNSSEC の有効化。
- セルフホスト DNS との統合: DNS forwarding、DNS server policy。
- private/public zone と split-horizon DNS。
- Cross-project binding と DNS peering の構成。
- GKE 向けの Cloud DNS / external-DNS operator。
Section 4: Configuring and implementing hybrid and multicloud network interconnectivity (~16%)
4.1 Cloud Interconnect
- Dedicated Interconnect 接続と VLAN attachment の作成。
- Partner Interconnect 接続と VLAN attachment、Layer 2 と Layer 3 の違い。
- Cross-Cloud Interconnect 接続と VLAN attachment。
- HA VPN over Cloud Interconnect の構成。
- 99.9% / 99.99% SLA トポロジーの実装。
4.2 Site-to-site IPSec VPN
- オンプレ VPN ゲートウェイに対する HA VPN 構成。
- 別 VPC への HA VPN 構成。
- Classic VPN (route-based / policy-based) 構成。
4.3 Cloud Router
- BGP 属性: ASN、route priority/MED、link-local アドレス、認証 (MD5)。
- BFD (Bidirectional Forwarding Detection) の構成。
- custom-advertised routes / custom-learned routes。
- VPC の legacy / standard best path selection の選択。
4.4 Network Connectivity Center (Hybrid)
- hybrid spoke (VPN, VLAN attachment) の作成。
- site-to-site データ転送の確立。
- Router Appliance (RA) の作成。
- transitivity (推移ルーティング) の一般的問題の解決。
Section 5: Managing, monitoring, and troubleshooting network operations (~14%)
5.1 Google Cloud Observability によるロギング/モニタリング
- 各種ネットワークコンポーネントの Cloud Logging 有効化と確認: Cloud VPN / Cloud Router / VPC Service Controls / Cloud NGFW / Firewall Insights / VPC Flow Logs / Cloud DNS / Cloud NAT / NCC。
- ネットワーク メトリクスの監視: Cloud VPN、Cloud Interconnect、VLAN attachment、Cloud Router、LB、Cloud Armor、Cloud NAT。
5.2 接続性のトラブルシュート
- Application LB での traffic drain / redirect。
- VPN の管理とトラブルシュート。
- Cloud Interconnect 問題のトラブルシュート。
- Cloud Router の BGP peering トラブルシュート。
- VPC Flow Logs、Firewall logs、Packet Mirroring の活用。
5.3 Network Intelligence Center (NIC)
- Network Topology: スループット/トラフィックフロー可視化。
- Connectivity Tests: ルート/ファイアウォール設定のミス診断。
- Performance Dashboard: パケロス/レイテンシ (Google-wide & project scoped)。
- Firewall Insights: ルールの監視/最適化。
- Network Analyzer: 失敗・準最適構成・使用率警告の自動検出。
- Flow Analyzer + VPC Flow Logs: ネットワークトラフィック評価。
Section 6: Configuring, implementing and managing a cloud network security solution (~13%)
6.1 Google Cloud Armor
- edge / backend security policy の構成・アタッチ。
- WAF ルール: SQLi / XSS / RFI など (preconfigured WAF rules)。
- Advanced Network DDoS Protection と Adaptive Protection。
- rate limiting の構成。
- bot management。
- Google Threat Intelligence の適用。
6.2 Cloud NGFW と VPC Firewall ルール
- ファイアウォール戦略: VPC firewall rules、Cloud NGFW、hierarchical firewall policies、サードパーティ統合。
- hierarchical 環境での effective policy の理解。
- GKE と Cloud Load Balancing をサポートする NGFW 構成。
- VPC firewall rules / Cloud NGFW (regional / global / hierarchical) policies の作成とトラブルシュート。
- Cloud NGFW Enterprise の L7 パケットインスペクション。
- VPC firewall rules から Cloud NGFW policies への移行。
- ルール条件: priority、protocol、direction、source、destination。
- VPC / Firewall Rules Logging。
- マイクロセグメンテーション: metadata、(secure) tags、service account、network tag。
- Cloud NGFW のティア: Essentials / Standard / Enterprise。
6.3 公衆 egress の構成 (Public Cloud NAT, Secure Web Proxy)
- public Cloud NAT IP の構成: 自動 / 手動 IP 割り当て。
- Cloud NAT の static / dynamic port allocation。
- Secure Web Proxy の構成。
6.4 セルフマネージド NVA と Packet Mirroring
- multi-NIC VM (NGFW appliance) による inter-VPC ルーティング/検査。
- HA multi-NIC VM ルーティング向け Internal LB as next hop。
- HA multi-NIC VM ルーティング向け policy-based routes。
- Out-of-band Network Security Integration 戦略。
- セルフマネージド collector への Packet Mirroring 構成。
付録: 出題比率まとめ
Section 1 (設計) ████████████████████ 21%
Section 2 (実装) ███████████████████ 20%
Section 3 (マネージド) ████████████████ 16%
Section 4 (Hybrid/Multi) ████████████████ 16%
Section 5 (運用/監視) ██████████████ 14%
Section 6 (セキュリティ) █████████████ 13%