section4_問題集

Section 4 問題集 — ハイブリッド・マルチクラウド接続


Q1

オンプレと GCP 間で Dedicated Interconnect 99.99% SLA を構築したい。最小要件は?

A. 1 metro / 2 attachments / 1 Cloud Router
B. 2 metros (異 PoP) / 4 attachments / 2 Cloud Routers / global dynamic routing
C. 1 metro / 4 attachments / 1 Cloud Router
D. 2 metros / 2 attachments / 1 Cloud Router

解答**B**。99.99% は 2 metros + 4 attachments + 2 Cloud Routers + global routing + active/active が公式要件。

Q2

帯域 ≤ 50 Mbps、暗号化必須、最小コストの常時接続が必要。最適な構成は?

A. Dedicated Interconnect 99.9%
B. Partner Interconnect
C. HA VPN
D. Cloud Router Direct Peering

解答**C**。HA VPN は IPsec 暗号化 + 99.99% SLA (2 tunnels active/active) を低コストで提供。

Q3

Cloud Interconnect の物理回線上を暗号化したい (compliance 要件)。選択肢は (複数選択)?

A. MACsec on Cloud Interconnect
B. HA VPN over Cloud Interconnect
C. Cloud Armor
D. VPC Service Controls

解答**A, B**。物理層 (L2) の MACsec か、L3 IPsec の HA VPN over Interconnect。

Q4

GCP の Cloud Router で BGP の最適経路選択を、Cloud Router の route priority を MED に加算した値で行いたい。設定すべきモードは?

A. Legacy best-path selection
B. Standard best-path selection
C. Regional dynamic routing
D. Custom advertisement mode

解答**B**。Standard mode が新しい挙動で、`--advertised-route-priority` が MED に加算され、より明確な経路制御が可能。

Q5

Cloud Router の BGP セッションで、障害検出を 1 秒以内にしたい。有効化すべき機能は?

A. MD5 authentication
B. BFD (Bidirectional Forwarding Detection)
C. AS-Path prepending
D. Static route

解答**B**。BFD はサブセカンドで peer の到達性を検出する。

Q6

AWS と GCP を Public Internet 経由せずに物理接続したい。最適な方式は?

A. Cloud VPN to AWS
B. Cross-Cloud Interconnect
C. Direct Peering
D. Verified Peering Provider

解答**B**。Cross-Cloud Interconnect は AWS Direct Connect 等と物理的に相互接続するサービス。

Q7

NCC hub を作って、複数のオンプレ拠点 + 3 つの VPC を統合接続。さらにオンプレ拠点間の transitive 通信も必要。必要なリソースは?

A. NCC hub + VPC spokes (3 つ) + Hybrid spokes (拠点ごと)
B. VPC Peering を全 VPC + オンプレで張る
C. Cloud Router を全リージョンに配置
D. Shared VPC のみ

解答**A**。NCC は VPC + hybrid を 1 つの hub で transitive 接続するための公式機構。

Q8

HA VPN を構築する際の制約として 正しいものは?

A. Static route のみで動く
B. BGP が必須 で Cloud Router が必要
C. 1 interface だけで 99.99% SLA を達成できる
D. policy-based 設定が必要

解答**B**。HA VPN は BGP + Cloud Router が必須。99.99% SLA は 2 interfaces 構成。

Q9

オンプレからの BGP route が、特定の prefix だけ Cloud Router に学習されないようにしたい。設定は?

A. Cloud Router で custom learned routes を設定し、許可する prefix を明示
B. オンプレ側で広告しないようにする
C. VPC Peering で除外する
D. firewall rule で deny する

解答**A** または **B**。Cloud Router の **custom learned routes** で受け入れる prefix を制御可能。実運用では B (オンプレ側で広告制御) も一般的。

Q10

HA VPN over Cloud Interconnect を使う典型シナリオは?

A. Cloud Interconnect の帯域を増やす
B. Cloud Interconnect 上の通信に IPsec 暗号化を加える
C. SD-WAN との統合
D. BGP peering を不要にする

解答**B**。Interconnect 自体は暗号化されないため、compliance 要件で IPsec を載せる構成。