PCNE Study Hub
Home
Roadmap
S1
S2
S3
S4
S5
S6
Quiz
用語
📝 ランダムクイズ (15 問)
全 Section から抽出した実戦クイズ。1 問ずつ採点ボタンを押して進めてください。
Q1
S1
3 つの VPC を相互通信させたい (transitive 必須)。
A. VPC Peering フルメッシュ
B. Cloud VPN を 3 本
C. Network Connectivity Center (VPC spokes)
D. Shared VPC
採点
C。
Peering は transitive 不可、NCC が公式解決策。
Q2
S1
Subnet を
/22
から
/20
に拡張したい。
A.
gcloud compute networks subnets expand-ip-range
B. subnet 再作成
C. VPC ごと作り直す
D. Cloud Router の static route 追加
採点
A。
拡張のみ可、縮小不可。
Q3
S2
2 NVA を Active/Active で配置、HA 経路化したい。
A. next-hop-instance で 2 NVA を個別指定
B. Internal Passthrough LB を next-hop-ilb に
C. External LB を NVA 前に
D. Cloud NAT で代替
採点
B。
ILB next-hop が HA NVA の公式パターン。
Q4
S3
グローバル HTTPS + WAF + CDN。
A. Regional External Application LB
B. External Passthrough NLB
C. Global External Application LB + Cloud Armor + Cloud CDN
D. Internal Application LB
採点
C。
Global External Application LB は Cloud Armor + CDN を統合。
Q5
S3
Internal Application LB のオンプレ backend は?
A. Internet NEG
B. Hybrid NEG
C. Serverless NEG
D. Zonal NEG
採点
B。
Hybrid NEG は Internal LB 用のオンプレ/他クラウド NEG。
Q6
S4
99.99% Dedicated Interconnect 必要要素は (3つ選択)?
A. 2 metros
B. 4 VLAN attachments
C. 2 Cloud Routers (global routing)
D. Static routing
採点
A, B, C。
Static は不可、BGP 必須。
Q7
S4
Cloud Router の BGP 障害検出を sub-second に。
A. MD5 authentication
B. BFD
C. Hold timer 短縮
D. AS-Path prepending
採点
B。
BFD で sub-second 検出。
Q8
S4
AWS と GCP を Public Internet を経由せず物理接続。
A. Cloud VPN to AWS
B. Cross-Cloud Interconnect
C. Direct Peering
D. Verified Peering Provider
採点
B。
CCI は他クラウドへの物理回線。
Q9
S5
VM A→B に通信不可。最初に使うツールは?
A. Network Topology
B. Performance Dashboard
C. Connectivity Tests
D. Packet Mirroring
採点
C。
経路と blocker を即診断。
Q10
S5
LB の HC が落ちる。最初に確認は?
A. backend CPU
B. firewall で 35.191.0.0/16 と 130.211.0.0/22 許可確認
C. Cloud DNS 設定
D. Cloud NAT
採点
B。
Google HC source range の許可漏れが最頻ミス。
Q11
S6
全プロジェクトで RDP (3389) を強制 deny。
A. 各 VPC firewall rule で deny
B. Hierarchical firewall policy at org
C. Cloud Armor
D. VPC-SC
採点
B。
Hierarchical FW は配下プロジェクトに強制適用。
Q12
S6
L7 TLS 検査 + IPS が要件。
A. Cloud NGFW Essentials
B. Cloud NGFW Standard
C. Cloud NGFW Enterprise
D. Cloud Armor
採点
C。
L7 inspection と IPS は Enterprise のみ。
Q13
S6
egress URL allow list で `*.github.com` のみ。
A. Cloud NAT で blockhole
B. Cloud Armor backend policy
C. Secure Web Proxy
D. VPC firewall rule
採点
C。
SWP は L7 URL/Host filter。
Q14
S1
マルチプロジェクト集中 NW 管理。
A. VPC Peering メッシュ
B. Default network
C. Shared VPC + subnet level networkUser
D. Cloud VPN メッシュ
採点
C。
subnet level がベスト。
Q15
S1
2 VPC が同じ CIDR で衝突。統合したい。
A. Private NAT (NCC) で重複 IP 解決
B. VPC Peering
C. Cloud NAT
D. Cloud Interconnect
採点
A。
Private NAT は重複 IP の公式解。
採点目安
正答数
レベル
14+ / 15
合格圏内 (受験予約 OK)
11-13
もう 1〜2 週弱点復習
8-10
学習資料・用語集を再周回
≤7
ロードマップ
に戻る