Configure a static route to an on‑prem resource reachable via a Cloud VPN gateway that uses policy‑based routing. Which next hop should the route use?
Choose an answer
Tap an option to check your answer.
Correct answer: The name and region of the Cloud VPN tunnel.
Why this is the answer
When configuring a static route in Google Cloud for resources reachable through a policy-based Cloud VPN gateway, the next hop must be specified as the Cloud VPN tunnel itself, identified by its name and region. This tells Google Cloud to direct traffic for the specified destination CIDR range through that particular VPN tunnel. The default internet gateway is incorrect because it routes traffic to the public internet, not to a private on-premises network via VPN. The IP address of the Cloud VPN gateway is incorrect because Google Cloud's routing mechanism for VPN tunnels uses the tunnel resource itself as the next hop, not its external IP. The IP address of the instance on the remote side of the VPN tunnel is incorrect because the next hop should be the entry point into the VPN, not an endpoint within the remote network.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed