Google Professional Cloud Network Engineer

Google Professional Cloud Network Engineer

Get started today

Ultimate access to all questions.


Your company's on-premises network is connected to a VPC via a Cloud VPN tunnel. The VPC has a static route (0.0.0.0/0) with the VPN tunnel as its next hop, causing all internet-bound traffic to route through the on-premises network. You set up Cloud NAT in one region to translate primary IP addresses of Compute Engine instances, expecting their internet traffic to exit directly from the VPC instead of the on-premises network. However, VM traffic is not being translated as intended. What should you do?