All internet-bound traffic must return to on-prem via HA VPN before egress, while VMs must reach private Google APIs at 199.36.153.4/30. How do you configure routes?
Choose an answer
Tap an option to check your answer.
Correct answer: Announce 0.0.0.0/0 from the on-prem router with MED 1000. Create a custom 199.36.153.4/30 route priority 1000 next hop = default internet gateway..
Why this is the answer
The correct solution ensures all internet-bound traffic hairpins through on-premises, while allowing direct access to Google APIs. Announcing 0.0.0.0/0 from on-prem with a high MED (e.g., 1000) makes the VPN the preferred path for all internet-bound traffic, fulfilling the hair-pinning requirement. The custom route for 199.36.153.4/30 with a next hop of the default internet gateway overrides the VPN route for this specific destination, enabling direct access to private Google APIs. Incorrect options fail because: Setting a custom 0.0.0.0/0 route with next hop internet gateway would bypass the on-prem hair-pinning. Setting the 199.36.153.4/30 route to the VPN tunnel would prevent direct access to Google APIs. Announcing 0.0.0.0/0 from on-prem with a low MED (e.g., 500) would make it the preferred route, but the other parts of the options are incorrect.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed