PCNE 用語集
A〜Z 順。試験直前の暗記用。頻出度: ★★★ (毎回出る) / ★★ (高確率) / ★ (出ることがある)
A
Adaptive Protection ★★
Cloud Armor の ML ベース異常検出機能。DDoS や大量リクエストパターンを自動学習し、suggested rule を提示。
Advanced Network DDoS Protection ★★
Cloud Armor の機能で Network LB (L4) を保護。Volumetric attack に対する mitigation。
Anycast IP ★★
External Passthrough NLB や Global LB で利用される 1 IP を複数地点で広報する方式。最寄りリージョンに自動誘導。
ASN (Autonomous System Number) ★★★
BGP の自律システム番号。GCP では 16-bit (1-64511) または private (64512-65534) または 4-byte。Cloud Router 設定で指定。
Authorized Networks ★★
GKE control plane 公開 endpoint へのアクセスを制限する CIDR リスト。最大 100 件。
Auto-mode VPC ★
全リージョンに自動で /20 subnet を作る VPC。本番では非推奨、設計自由度低。
B
BFD (Bidirectional Forwarding Detection) ★★
BGP の sub-second 障害検出を可能にするプロトコル。Cloud Router でサポート。
BGP (Border Gateway Protocol) ★★★
AS 間のルーティング情報交換プロトコル。Cloud Interconnect/VPN で eBGP セッションを Cloud Router と peer 間で確立。
BYOIP (Bring Your Own IP) ★
持ち込みパブリック IP を GCP の external IP として利用。
C
Classic VPN ★
旧来の Cloud VPN。policy-based / route-based の選択肢あり。新規構築は HA VPN を推奨。
Cloud Armor ★★★
GCP のマネージド WAF + DDoS 防御。edge policy / backend policy、preconfigured WAF rules、Adaptive Protection、Threat Intelligence、Rate Limiting、Bot Management。
Cloud CDN ★★
グローバル LB に統合された CDN。MIG / Cloud Storage / Cloud Run / Internet NEG が origin。
Cloud DNS ★★★
GCP のマネージド DNS。public / private / forwarding / peering / reverse zone。DNSSEC は public のみ。
Cloud Interconnect ★★★
オンプレと GCP の物理回線接続。Dedicated / Partner / Cross-Cloud Interconnect。
Cloud NAT ★★★
egress NAT for VPC。VM が external IP 不要でインターネット接続。subnet 単位設定、Cloud Router 経由。
Cloud NGFW (Next Generation Firewall) ★★★
Cloud Firewall の新世代。Essentials / Standard / Enterprise の 3 ティア。
Cloud Router ★★★
マネージド BGP スピーカー。Interconnect/VPN/RA との peer。
Cloud VPN ★★★
IPsec VPN。Classic / HA VPN。HA VPN は BGP 必須。
Connectivity Tests ★★★
Network Intelligence Center の機能。src/dst を指定して経路と blocker を診断。
Cross-Cloud Interconnect ★★
GCP と AWS/Azure/OCI/Alibaba の 物理回線接続。Public Internet を経由しない。
Cross-region Internal Application LB ★★
複数リージョンの VPC 内ワークロードに対する Internal L7 LB。最近 GA。
Custom-mode VPC ★★★
subnet を手動定義する VPC。本番標準。
D
Dataplane V2 ★★
GKE の eBPF ベース dataplane。Network Policy 高速化、FQDN policy。一度有効化すると無効化不可。
Dedicated Interconnect ★★★
Google PoP に直接物理接続。10G/100G。MACsec 対応。
DDoS (Distributed Denial of Service) ★★
分散型サービス拒否攻撃。Cloud Armor が L7、Advanced Network DDoS が L4 を保護。
DNS-based Endpoint (GKE) ★★
GKE control plane への公開 IP 不要な kubectl アクセス方式。IAM 認証。最新推奨。
DNS Peering ★★
1 VPC の private zone を別 VPC から参照可能にする。片方向。
DNSSEC ★
DNS の改竄防止。public zone のみ対応、DS レコードを registrar に登録必須。
Dynamic Port Allocation (Cloud NAT) ★★
NAT のポート使用量に応じて自動拡張する機能。ポート枯渇対策。
Dynamic Routing Mode ★★★
VPC の BGP route 伝搬モード。Global (全リージョンで learned route を共有) / Regional (同リージョンのみ)。99.99% Interconnect は global 必須。
E
eBPF ★
Linux カーネルのプログラマブル機能。GKE Dataplane V2 の基盤。
Edge Availability Domain (EAD) ★★
Dedicated Interconnect で metro 内の冗長 PoP 区分。99.9% は 2 EAD、99.99% は 2 metros × 2 EAD。
Endpoint-Independent Mapping (Cloud NAT) ★
P2P (STUN/TURN, VoIP) で同 source からは同 external IP/Port にマップ。
External Passthrough NLB ★★★
L4 Network LB (passthrough)。Anycast IP、クライアント IP 保持。
F
Failover Routing Policy (Cloud DNS) ★
Primary + backup レコード。Health check で自動切替。
FQDN Object (Cloud NGFW) ★★
NGFW Standard で FQDN ベースの allow/deny ルールを記述可能にする。
Firewall Insights ★★
Firewall rule の shadowed / unused / overly permissive 自動検出。
Forwarding Zone (Cloud DNS) ★★
特定ドメインを別 DNS にフォワード。outbound のオンプレ統合に使う。
G
Geolocation Routing Policy (Cloud DNS) ★★
クライアント発信元の地域でレコードを振り分け。
Global External Application LB ★★★
グローバル L7 LB。Cloud Armor / CDN 統合。
Global Dynamic Routing ★★★
VPC レベル設定。Cloud Router の BGP 学習が全リージョン subnet に伝搬。
Google Cloud Armor → Cloud Armor 参照
Google Threat Intelligence ★★
Cloud Armor の preconfigured IP リスト (known malicious, Tor exit, etc.)。
H
HA VPN ★★★
2 interfaces + 2+ tunnels で 99.99% SLA。BGP 必須。
HA VPN over Cloud Interconnect ★★
Interconnect 上に IPsec を載せる compliance 暗号化構成。
Health Check (LB) ★★
LB backend の生存確認。Google source: 35.191.0.0/16, 130.211.0.0/22 を firewall で許可必須。
Hierarchical Firewall Policy ★★★
Org / folder level の FW policy。配下プロジェクトに強制適用。goto_next で次階層に評価渡し可。
Hybrid NEG ★★
Internal LB にオンプレ/他クラウドを backend 登録するための NEG。
Hybrid Spoke (NCC) ★★
NCC のオンプレ・他クラウド接続用 spoke。VPN tunnel / VLAN attachment / Router Appliance。
I
IAP (Identity-Aware Proxy) ★
TCP forwarding 経由で SSH/RDP。source range: 35.235.240.0/20。
IP Masquerade Agent ★
GKE の Pod → 外部 SNAT 制御エージェント。nonMasqueradeCIDRs で除外。
Inbound DNS Server Policy ★★
オンプレから GCP private zone を解決する仕組み。VPC に inbound IP を払い出す。
Internal Passthrough NLB ★★★
L4 Internal LB。IP/Port 保持。Next Hop に指定可能で HA NVA の定番。
Internet NEG ★★
External LB の backend にオンプレ/他クラウドの FQDN/IP を登録。
L
Load Balancer (LB) 種別 ★★★
- Global External Application LB
- Regional External Application LB
- Cross-region Internal Application LB
- Regional Internal Application LB
- Global / Regional External Proxy NLB
- Cross-region / Regional Internal Proxy NLB
- External / Internal Passthrough NLB
Legacy Best-Path Selection (Cloud Router) ★
Cloud Router の route priority を MED に加算しない旧モード。Standard mode 推奨。
M
MACsec ★★
Cloud Interconnect の 物理層 L2 暗号化。Dedicated / Cross-Cloud Interconnect で対応。
MED (Multi-Exit Discriminator) ★★★
BGP attribute。小さいほど優先。Cloud Router の --advertised-route-priority が MED として広告。
MIG (Managed Instance Group) ★★
LB の backend として典型。自動スケーリング + 自動ヒーリング。
MTU (Maximum Transmission Unit) ★★
VPC: 1460 デフォルト、1500/8896 サポート。Interconnect/VPN で揃える必要。VPC 作成時のみ設定可。
N
NEG (Network Endpoint Group) ★★★
LB backend の汎用形式。Zonal / Internet / Serverless / Hybrid / PSC NEG。
Network Analyzer ★★
継続的に misconfiguration / suboptimal を自動検出。Network Intelligence Center。
Network Connectivity Center (NCC) ★★★
hub-spoke の集中接続管理。VPC spoke / Hybrid spoke / Producer spoke。Transitive 可能。
Network Intelligence Center (NIC) ★★★
5 ツール: Network Topology / Connectivity Tests / Performance Dashboard / Firewall Insights / Network Analyzer。
Network Tag ★★
VPC firewall rule や route の対象指定。IAM 制御不可。Secure tag の方が新しい。
Network Topology ★★
NIC のツール。トラフィックフロー可視化。
NVA (Network Virtual Appliance) ★★
サードパーティ FW/IPS/SD-WAN VM。Multi-NIC + Internal Passthrough LB next-hop で HA。
P
Packet Mirroring ★★
VPC トラフィックをコレクター ILB へコピー。out-of-band IDS/IPS 連携。
Partner Interconnect ★★
パートナー回線経由の Cloud Interconnect。50M〜50G。L2 / L3 接続方式。
Performance Dashboard ★★
NIC のツール。Google-wide vs project-scoped の latency / packet loss 比較。
Policy-based Routing (PBR) ★★
source / protocol で経路を分岐させる route 機能。
Private Google Access ★★★
VPC 内 VM が internal IP で *.googleapis.com にアクセス。subnet flag で有効化。
Private NAT ★★
NCC の機能で重複 IP 問題を解決する RFC6598 ベース NAT。
Private Service Connect (PSC) ★★★
4 モード:
- Endpoint (consumer 側 IP)
- Backend (LB backend)
- Interface (producer → consumer 方向)
- for Google APIs (
googleapis.comを private IP で)
Private Services Access (PSA) ★★
Google マネージドサービス (Cloud SQL, Memorystore 等) への private 接続。VPC Peering 経由。
Producer Spoke (NCC) ★★
PSC endpoint を NCC hub に propagation。
Proxy-only Subnet ★★
Regional Application LB / Internal Proxy NLB で必要な専用 subnet (/26 推奨)。
PUPI (Privately Used Public IP) ★
パブリック IP 範囲を VPC 内 private で利用。Peer 越しは export/import を明示。
R
Rate Limiting (Cloud Armor) ★★
src IP / cookie / header ベースの RPS 制限。
Regional Dynamic Routing ★★
BGP 学習が同リージョン subnet にのみ伝搬。
Router Appliance (RA) ★★
NCC hybrid spoke。SD-WAN や NVA の BGP セッションを VM が終端。
Routing Policy (Cloud DNS) ★★
WRR / Geolocation / Failover / Health Checked Multi-target。
S
Secure Tags ★★
network tag より新しい、IAM 制御可能なタグ。
Secure Web Proxy (SWP) ★★★
L7 egress URL/Host フィルタマネージドプロキシ。TLS 検査可能。
Serverless NEG ★★
Cloud Run / App Engine / Cloud Functions / API Gateway を LB backend に。
Session Affinity ★★
LB のスティッキー設定。CLIENT_IP / GENERATED_COOKIE / HEADER_FIELD / HTTP_COOKIE / CLIENT_IP_PORT_PROTO。
Shared VPC ★★★
host project + service projects。subnet level の networkUser IAM。
SLA (Service Level Agreement) ★★
- HA VPN: 99.99% (2 tunnels active/active)
- Interconnect: 99.9% (1 metro) / 99.99% (2 metros)
- Classic VPN: 99.9%
Standard Best-Path Selection ★★
Cloud Router の route priority を MED に加算して経路選択。
Standard Tier vs Premium Tier ★★
- Premium: Google backbone 経由でグローバル
- Standard: Public Internet 経由で安価、Regional のみ
Static / Dynamic Port Allocation (Cloud NAT) → Dynamic Port Allocation 参照
Subnet Expand ★★
gcloud compute networks subnets expand-ip-range で範囲拡張。縮小不可。
T
Threat Intelligence (Cloud Armor) ★★
preconfigured IP リスト (Tor, known malicious, public clouds など)。
Transitivity ★★★
3 つ以上の VPC を相互接続する性質。VPC Peering 不可、NCC 可。
V
VPC (Virtual Private Cloud) ★★★
GCP の仮想ネットワーク。Global, subnet が Regional。Auto-mode / Custom-mode / Default。
VPC Flow Logs ★★
subnet 単位の packet sampling log。BigQuery 連携で分析。
VPC Network Peering ★★★
2 VPC 間直接接続。Transitive 不可、Cloud DNS 共有しない。
VPC Service Controls (VPC-SC) ★★★
API レベル境界。BigQuery 等の access 制限。dry-run mode あり。
Verified Peering Provider ★
認定パートナー経由で Google サービスへ peering。
W
WAF (Web Application Firewall) ★★★
Cloud Armor の preconfigured ruleset (SQLi, XSS, RFI, LFI, RCE, etc.)。
WRR (Weighted Round Robin) — Cloud DNS routing policy ★
重み付き分散。canary release。
略号一覧
| 略号 | 正式 |
|---|---|
| BGP | Border Gateway Protocol |
| BFD | Bidirectional Forwarding Detection |
| CIDR | Classless Inter-Domain Routing |
| ECMP | Equal-Cost Multi-Path |
| EAD | Edge Availability Domain |
| GKE | Google Kubernetes Engine |
| HA | High Availability |
| IAP | Identity-Aware Proxy |
| MED | Multi-Exit Discriminator |
| MIG | Managed Instance Group |
| MTU | Maximum Transmission Unit |
| NAT | Network Address Translation |
| NCC | Network Connectivity Center |
| NEG | Network Endpoint Group |
| NGFW | Next Generation Firewall |
| NIC | Network Intelligence Center |
| NLB | Network Load Balancer |
| NVA | Network Virtual Appliance |
| PBR | Policy-Based Routing |
| PoP | Point of Presence |
| PSA | Private Services Access |
| PSC | Private Service Connect |
| PUPI | Privately Used Public IP |
| RA | Router Appliance |
| RPS | Requests Per Second |
| SLA | Service Level Agreement |
| SNAT | Source NAT |
| SWP | Secure Web Proxy |
| VPC | Virtual Private Cloud |
| VPC-SC | VPC Service Controls |
| WAF | Web Application Firewall |
| WRR | Weighted Round Robin |