Q: 11
You are maintaining a Shared VPC in a host project. Several departments within your company have
infrastructure in different service projects attached to the Shared VPC and use Identity and Access
Management (IAM) permissions to manage the cloud resources in those projects. VPC Network
Peering is also set up between the Shared VPC and a common services VPC that is not in a service
project. Several users are experiencing failed connectivity between certain instances in different
Shared VPC service projects and between certain instances and the internet. You need to validate the
network configuration to identify whether a misconfiguration is the root cause of the problem. What
should you do?
Options
Discussion
Not D here-enabling Flow Logs is good for traffic analysis, but C directly checks network paths for misconfigurations in real-time. Connectivity Tests flag routing/firewall issues fast. Think C is the move, unless I'm missing something subtle.
Its D (saw similar question on a practice set).
Totally see why D is tempting, but C makes more sense to me. Connectivity Tests in Network Intelligence Center actually lets you visualize and verify the routes/ACLs/firewall rules between endpoints for diagnosing misconfig fast. Pretty sure that's the best fit here, but open to a counterpoint.
Be respectful. No spam.