Design an IPsec VPN from a single on-prem VPN device (one public IP) to a Google VPC with a minimum 99.99% SLA and minimal setup effort. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: 1. Create one HA VPN gateway. Create one tunnel for each of the two HA VPN gateway interfaces. Terminate each of the two tunnels on the single public IP address on the on‑prem device..
Why this is the answer
The correct answer ensures high availability (99.99% SLA) with minimal setup effort for a single on-premises VPN device. Google Cloud's HA VPN requires two tunnels, each from a different interface of the HA VPN gateway, even when connecting to a single peer IP address. This configuration allows Google Cloud to maintain the SLA by using redundant internal paths. The on-premises device then terminates both tunnels on its single public IP. Option 1 is incorrect because it suggests creating two separate HA VPN gateways, which is unnecessary and more complex for a single on-prem device. Option 2 is incorrect because Classic VPN does not offer the 99.99% SLA required. Option 3 is incorrect because it requires replacing the on-prem device, which contradicts the "minimal setup effort" requirement and the constraint of using the existing single public IP.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed