Google PCNE: Load Balancing, Cloud CDN and Global Traffic Management — Study Guide

Part of the Google Professional Cloud Network Engineer — Study Guide. Practice with verified answers in the Google exam hub, or take timed practice tests on ExamRoll.io.

Overview

This section explains how Google Cloud Load Balancing, Cloud CDN, and global traffic management work together to deliver resilient, performant, and secure services. It covers load-balancer families and selection, proxy versus passthrough behavior, backend and routing components, failover and capacity management, Cloud CDN caching and origin protections, anycast and cross-region designs, DNS steering and health checks, observability, and design patterns for robust global entry points.

Load-balancer families, selection, and data-plane behavior

Google Cloud provides external and internal load balancers with distinct scope, protocol, and data-plane characteristics. Choosing the right one aligns protocol needs, geography, and operational controls.

Layer and termination trade-offs:

Scope and IP families:

Selection criteria highlights:

Backend services, routing objects, health, and traffic stickiness

Core data-plane objects:

Health checks and failover:

URL maps and routing:

Example: minimal URL map with HTTPS redirect and default backend

Session affinity and draining:

Capacity and autoscaling:

Security at backends:

Example: restrict clients and health checks to a backend-tagged group

Cloud CDN, cache policy, and origin protection

Cloud CDN integrates with the external Application Load Balancer to cache responses at edge POPs, reducing latency and offloading origin capacity.

Cache modes and TTLs:

Cache keys:

Signed requests:

Compression and correctness:

Origin security:

Failure modes and trade-offs:

Global traffic management, DNS steering, observability, and resilient entry points

Anycast front doors and cross-region failover:

Regional internal traffic management:

Cloud DNS routing policies and health checks:

Observability and diagnostics:

Resilient global entry-point design:

Example: firewall rule restricting client and health check ranges to tagged backends

Practical Problem Scenario

Acme Retail launches a global e-commerce platform needing low latency, strong security, and transparent failover across us-east1 and europe-west1 while serving static media efficiently. Only corporate offices and a partner CDN staging network should reach the private admin interface.

  1. Front door and backends
  1. URL map, routing, and redirects
  1. Cloud CDN policy
  1. Session affinity and draining
  1. Cross-region failover and autoscaling
  1. Admin interface restriction
  1. Backend firewall and origin security
  1. Cloud Armor
  1. Cloud DNS steering and health checks
  1. Observability

Hybrid Connectivity · All domains · Cloud DNS

Practice these questions → · Timed practice on ExamRoll.io →

Pass the whole exam — not just this question

You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.

Pass your exam →

Browse Google →

Related guides

All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product