---
tags:
- cloud
- l1
- flashcard-deck
- gcp-networking
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [GCP Troubleshooting](../../../../library/portal/topics.md) | **Domain:** Cloud
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
gcp-networking/0d1bfb72c9a5	gcp-networking	medium	gcp,networking,compute,compute	Explain Global Load Balancer.	It's a load balancing service distributing internet traffic across multiple regions to optimize service availability. It provides:\n* Global Presence: It offers a single anycast IP address for routing traffic to the nearest healthy instance, improving latency and service availability.	projects/knowledge/interview/gcp/110-explain-global-load-balancer.txt
gcp-networking/1434ccb1ffbd	gcp-networking	medium	gcp,networking,security	What is concept of shared VPC in GCP, also how do you setup a shared VPC ?	Shared VPC (Virtual Private Cloud) is a network resource that allows an organization to connect multiple projects to a common VPC network. This centralizes network management and administration while allowing resources from different projects to communicate securely within the same virtual network. It simplifies network setup, aids in resource sharing, and centralizes governance and security policies.	projects/knowledge/interview/gcp/063-what-is-concept-of-shared-vpc-in-gcp-also-how-do-y.txt
gcp-networking/2786fd7cfd05	gcp-networking	medium	gcp,networking,security	What is Cloud Load Balancing?	It's a service for distributing incoming network traffic across multiple resources, ensuring high availability and reliability. Offers various load balancing options: global (for HTTP(S) and TCP/SSL traffic), internal (for internal traffic within VPC), and network (for non-HTTP/S traffic). Automatically scales resources based on traffic demands.	projects/knowledge/interview/gcp/092-what-is-cloud-load-balancing.txt
gcp-networking/5bfebbc4c98c	gcp-networking	medium	gcp,networking,compute	What is Google Cloud CDN (Content Delivery Network)?	Google Cloud CDN is a distributed edge caching service for delivering content closer to users for lower latency and better performance.\n* Content Caching and Distribution: Cloud CDN caches web content at Google's globally distributed edge caches. This allows users to access content from a nearby edge location, reducing latency.	projects/knowledge/interview/gcp/115-what-is-google-cloud-cdn-content-delivery-network.txt
gcp-networking/74569fdf0084	gcp-networking	medium	gcp,networking,security	What is VPC Service Controls ?	VPC Service Controls is a GCP security feature allowing the restriction of data access between Google-managed services and the resources within a Virtual Private Cloud (VPC). It establishes a security perimeter around GCP resources, enabling organizations to define a security perimeter around APIs and services to prevent data exfiltration, maintaining data integrity and compliance. It ensures that sensitive data remains within the organization's specified boundaries even in the case of breaches.	projects/knowledge/interview/gcp/074-what-is-vpc-service-controls.txt
gcp-networking/92c27d6e8050	gcp-networking	medium	gcp,networking	What is Cloud Interconnect?	It's a service for connecting on-premises networks to GCP through dedicated and high-speed connections. It enables:\n* Fast and Reliable Connectivity: Direct connections with high bandwidth for better performance and reliability.\n* Hybrid Cloud Solutions: Facilitates hybrid cloud solutions by extending on-premises networks into GCP.\n* Reduced Latency: Helps in reducing latency and improving data transfer speeds.	projects/knowledge/interview/gcp/106-what-is-cloud-interconnect.txt
gcp-networking/cc3afb34384d	gcp-networking	medium	gcp,networking,security	Describe Google Virtual Private Cloud (VPC).	It's a global private network providing a virtual networking environment that allows users to connect GCP resources to each other and to the internet along with offering control over IP ranges, subnets, and network policies. It also enables custom network topologies and network security configurations.	projects/knowledge/interview/gcp/091-describe-google-virtual-private-cloud-vpc.txt
gcp-networking/a1b2c3d4e5f6	gcp-networking	easy	gcp,networking,vpc	What is a subnet in GCP, and how does it differ from other clouds?	In GCP, subnets are regional (not zonal). A single subnet spans all zones within a region. Each subnet has a primary IP range and can have secondary ranges for alias IPs (used by GKE for pod and service CIDRs). Unlike AWS, you do not create one subnet per AZ — one regional subnet covers all zones automatically.	training/interactive/knowledge/data/cards/gcp-networking.tsv
gcp-networking/b2c3d4e5f6a7	gcp-networking	easy	gcp,networking,firewall	How do GCP firewall rules work?	GCP firewall rules are applied at the VPC level and are stateful. Each rule specifies direction (ingress/egress), priority (0-65535, lower wins), action (allow/deny), target (all instances, specific tags, or service accounts), and protocols/ports. Rules are evaluated by priority — the first matching rule wins. The default network has pre-populated rules allowing internal traffic and ICMP.	training/interactive/knowledge/data/cards/gcp-networking.tsv
gcp-networking/c3d4e5f6a7b8	gcp-networking	medium	gcp,networking,nat	What is Cloud NAT and when do you use it?	Cloud NAT (Network Address Translation) provides outbound internet connectivity for VM instances without external IP addresses. It is regional and works at the VPC network level. Common uses: allowing private GKE nodes to pull container images, enabling private VMs to reach external APIs, and maintaining security by not exposing instances with public IPs. Cloud NAT does not support inbound connections — it is egress-only.	training/interactive/knowledge/data/cards/gcp-networking.tsv
gcp-networking/d4e5f6a7b8c9	gcp-networking	medium	gcp,networking,dns	What is Cloud DNS and what record types does it support?	Cloud DNS is a high-performance, scalable, managed authoritative DNS service. It supports A, AAAA, CNAME, MX, NS, PTR, SOA, SRV, TXT, and CAA record types. It offers both public zones (internet-facing) and private zones (VPC-internal resolution). Private zones enable split-horizon DNS where internal names resolve differently than public names. Cloud DNS supports DNSSEC for public zones.	training/interactive/knowledge/data/cards/gcp-networking.tsv
gcp-networking/e5f6a7b8c9d0	gcp-networking	hard	gcp,networking,lb	What are the different types of load balancers in GCP?	GCP offers: (1) Global external HTTP(S) LB — L7, anycast IP, URL-based routing, CDN integration. (2) Global external TCP/SSL Proxy — L4, for non-HTTP TCP traffic. (3) Regional external Network LB — L4, pass-through, preserves client IP. (4) Regional internal TCP/UDP LB — L4, for internal services within VPC. (5) Regional internal HTTP(S) LB — L7, for internal microservices. (6) Cross-region internal LB — L7, spans regions for internal traffic. Choice depends on protocol, scope (global vs regional), and whether traffic is internal or external.	training/interactive/knowledge/data/cards/gcp-networking.tsv
gcp-networking/f6a7b8c9d0e1	gcp-networking	medium	gcp,networking,peering	What is VPC Network Peering and what are its limitations?	VPC Network Peering connects two VPC networks so resources can communicate using internal IP addresses. Peering is non-transitive — if VPC-A peers with VPC-B, and VPC-B peers with VPC-C, VPC-A cannot reach VPC-C through VPC-B. Subnet IP ranges must not overlap. Peering works across projects and organizations. Routes, firewall rules, and IAM are managed independently in each VPC. Maximum of 25 peering connections per VPC network.	training/interactive/knowledge/data/cards/gcp-networking.tsv
gcp-networking/a7b8c9d0e1f2	gcp-networking	hard	gcp,networking,security	What are hierarchical firewall policies in GCP?	Hierarchical firewall policies allow organizations to enforce firewall rules at the organization or folder level, applying to all projects beneath them. Rules in higher-level policies are evaluated before VPC-level rules. This enables central security teams to enforce baseline rules (e.g., block known-bad IPs, require specific ports) that project-level admins cannot override. The evaluation order is: organization policy → folder policy → VPC firewall rules.	training/interactive/knowledge/data/cards/gcp-networking.tsv
gcp-networking/b8c9d0e1f2a3	gcp-networking	easy	gcp,networking,routing	How does routing work in a GCP VPC?	Every VPC has a system-generated default route (0.0.0.0/0) pointing to the default internet gateway, and automatically created subnet routes for each subnet's IP range. Custom static routes can be added for specific destinations. Dynamic routing (via Cloud Router using BGP) automatically exchanges routes with on-premises networks through VPN or Interconnect. VPCs can use regional or global dynamic routing mode.	training/interactive/knowledge/data/cards/gcp-networking.tsv
gcp-networking/c9d0e1f2a3b4	gcp-networking	medium	gcp,networking,vpn	What is Cloud VPN and what are its variants?	Cloud VPN securely connects your on-premises network to GCP VPC through IPsec tunnels. Classic VPN supports a single tunnel with static routing and up to 3 Gbps. HA VPN provides 99.99% SLA with two tunnels, supports dynamic routing via BGP with Cloud Router, and up to 3 Gbps per tunnel. HA VPN is recommended for production. Both encrypt traffic in transit but Cloud Interconnect is preferred for higher bandwidth needs.	training/interactive/knowledge/data/cards/gcp-networking.tsv
gcp-networking/d0e1f2a3b4c5	gcp-networking	hard	gcp,networking,gke	How does GKE networking work with VPC-native clusters?	VPC-native (alias IP) GKE clusters assign pod and service IP ranges from the VPC subnet's secondary ranges. Each node gets a /24 alias IP range for pods (max 110 pods per node by default). Benefits: pods are directly routable within the VPC without NAT, VPC firewall rules apply to pods, VPC Flow Logs capture pod traffic, and pods can communicate with other VPC resources using internal IPs. This replaces the older routes-based networking model.	training/interactive/knowledge/data/cards/gcp-networking.tsv

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- GCP Compute Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting
- GCP General Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting
- GCP Kubernetes Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting
- GCP Security Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting
- [GCP Troubleshooting](../../../../library/topics/gcp-troubleshooting/index.md) (Topic Pack, L1) — GCP Troubleshooting
- GCP Troubleshooting Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting

<!-- wiki:related:end -->
