Google Professional Cloud Network Engineer Exam Guide (2026)

If you can say whether the stem is buying a VPC path, a load balancer, a hybrid circuit, or a network security control, you are reading the right outline.
Professional Cloud Network Engineer is the Google Cloud certification for people who design, implement, and manage Google Cloud network infrastructure. The Professional Cloud Network Engineer certification page is the source for length, fee, question count, and recommended experience. The Professional Cloud Network Engineer exam guide is the source for the six scored sections and the product names used on the sitting.
The sitting is live. There is no prerequisite exam. Google recommends 3 or more years of industry experience, including 1 or more years designing and managing solutions using Google Cloud. This guide is for people scheduling the current standard exam, people who already hold the title and need the current task list, and people moving from Associate Cloud Engineer work into the network-engineer role.
Who this exam is for
Take it as a map of the Google Cloud network job the current exam guide scores. The audience profile asks for someone who can hold a VPC design, hold a hybrid path, hold a load balancer, and then stay with production when a flow, a firewall, or a BGP session breaks. The same profile expects Google Cloud networking products, not a private toolchain the sitting never names.
The responsibility list on the certification page is concrete. Design and plan a VPC network. Implement that network. Configure managed network services. Configure hybrid and multi-cloud interconnectivity. Manage, monitor, and troubleshoot network operations. Configure a cloud network security solution. Those six verbs are the six scored sections. The sitting punishes people who treat the role as a catalog of logos and rewards people who can read a constraint and pick the path, the balancer, the circuit, and the control that match it.
There is no required prior certification. The recommended experience is the gap check. If projects, Identity and Access Management roles, Cloud Storage buckets, and gcloud are still a catalog rather than weekly work, sit Associate Cloud Engineer first. The network sitting assumes those controls and then asks which subnet, which next hop, and which attachment to recommend. If the goal is the language of Google Cloud rather than the operation of a production network, Cloud Digital Leader is the closer match. Service definitions, shared responsibility, and product families belong there. They appear here as the vocabulary inside a path, not as the whole job.
Skip it if the work you actually want is deploying someone else's design day to day without owning the subnet, the route, or the interconnect. That job is Associate Cloud Engineer. Skip it if the work you actually want is the compute shape, the storage class, and a named case-study constraint across an entire solution. Those decisions are the Professional Cloud Architect sitting. Network products appear there as one recommendation among many. They are scored here as the entire job. Skip it if the stem you actually want is a Cloud Build trigger, an SLO, or a PromQL query. Network logs appear on this outline as VPC Flow Logs and Network Intelligence Center. They are not the Professional Cloud DevOps Engineer sitting. Skip it if the stem you actually want is a Beam job or a warehouse reservation. Private Service Connect appears here as a private path to a Google API. It is not the Professional Data Engineer sitting. Skip it if the work you actually want is the identity, the key, and the compliance folder. Cloud NGFW, Google Cloud Armor, Secure Web Proxy, and VPC Service Controls appear here as network controls. They are scored as the entire job on the Professional Cloud Security Engineer sitting.
The current professional network-engineer credential Google publishes for this role is this one. Use this page for the Professional Cloud Network Engineer task list. Use the Google Associate Cloud Engineer exam guide when the stem is an operator control that happens to sit on a firewall. Use the Google Professional Cloud Architect exam guide when the stem is a solution recommendation that happens to include a VPC. Use the Google Professional Cloud Security Engineer exam guide when the stem is an identity, a key, or a finding rather than a packet path. Use the Google Professional Cloud DevOps Engineer exam guide when the stem is a pipeline stage rather than a network control. Use the Google Professional Data Engineer exam guide when the stem is a data platform rather than a private API path.
Exam shape and how a pass is decided
The current exam guide publishes six sections and marks each weight as an approximation.
| Section | Weight | What gets tested |
|---|---|---|
| Designing and planning a Google Cloud VPC network | about 21% | Premium and Standard network tiers, high availability and disaster recovery, DNS topology, load balancer choice, GKE secondary ranges and control plane access, IAM roles for load balancer provisioning and Shared VPC subnet permissions, private services access, Private Service Connect, Serverless VPC Access, quotas and limits, standalone versus Shared VPC, VPC Network Peering, Network Connectivity Center mesh and star topologies, IPAM including IPv6, bring your own IP, privately used public IP, Private NAT, non-RFC 1918 ranges, global versus regional design, MTU, third-party network virtual appliances, Dedicated Interconnect, Partner Interconnect, Cloud VPN, Cross-Cloud Interconnect, Direct Peering, Verified Peering Provider, hybrid DNS, MACsec, and HA VPN over Cloud Interconnect |
| Implementing a VPC network | about 20% | VPC resources, firewall rules or policies, private services access subnets, VPC Network Peering, Shared VPC and the IAM needed to use a shared subnet, Private Google Access, expanding subnet ranges after creation, VPC Service Controls, static and dynamic routing, Cloud Router, global or regional dynamic routing, network tags and priority, policy-based routing, an internal load balancer as a next hop, custom route import and export, Network Connectivity Center spoke types, Private NAT and Private Service Connect propagation, CIDR filters, VPC-native GKE with alias IPs, private clusters, authorized networks, a DNS-based control plane endpoint, GKE Dataplane V2, SNAT and IP Masquerade, GKE network policies, extra Pod ranges, and Cloud DNS with kube-dns |
| Configuring managed network services | about 16% | Internal or external, regional or global, application, proxy, or passthrough load balancers, network endpoint groups, managed instance groups, balancing method, session affinity, serving capacity, URL maps, health checks, global access, GKE Gateway controller, GKE Ingress controller, Application Load Balancer traffic splitting, traffic mirroring, URL rewrites, Cloud CDN for managed instance groups, Cloud Storage, Cloud Run, internet NEGs, and third-party object storage, cache invalidation, Cloud DNS zones and records, geolocation and failover policies, DNSSEC, forwarding and server policies, public and private zones, split-horizon DNS, cross-project binding, and DNS peering |
| Configuring and implementing hybrid and multicloud network interconnectivity | about 16% | Dedicated Interconnect and VLAN attachments, Partner Interconnect Layer 2 versus Layer 3, Cross-Cloud Interconnect, HA VPN over Cloud Interconnect, 99.9% and 99.99% interconnect SLAs, HA VPN to on-premises gateways and to other VPC networks, Classic VPN route-based and policy-based tunnels, Cloud Router BGP attributes, BFD, custom advertised and custom learned routes, legacy versus standard best path selection, Network Connectivity Center hybrid spokes, site-to-site data transfer, and router appliances |
| Managing, monitoring, and troubleshooting network operations | about 14% | Cloud Logging for Cloud VPN, Cloud Router, VPC Service Controls, Cloud NGFW, Firewall Insights, VPC Flow Logs, Cloud DNS, Cloud NAT, and Network Connectivity Center, metrics for VPN, Interconnect, Cloud Router, load balancers, Cloud Armor, and Cloud NAT, draining and redirecting Application Load Balancer traffic, VPN and Interconnect troubleshooting, Cloud Router BGP issues, Packet Mirroring, Network Topology, Connectivity Tests, Performance Dashboard, Firewall Insights, Network Analyzer, and Flow Analyzer |
| Configuring, implementing and managing a cloud network security solution | about 13% | Cloud Armor edge and backend policies, WAF rules for SQL injection, cross-site scripting, and remote file inclusion, advanced network DDoS, Adaptive Protection, rate limiting, bot management, Google Threat Intelligence, VPC firewall rules versus Cloud NGFW versus hierarchical policies, effective hierarchical rules, Cloud NGFW for GKE and Cloud Load Balancing, layer 7 inspection on Cloud NGFW Enterprise, migration from VPC firewall rules to Cloud NGFW, rule criteria and logging, micro-segmentation with metadata, secure tags, service accounts, and network tags, Cloud NGFW Essentials, Standard, and Enterprise, Public Cloud NAT addressing and port allocation, Secure Web Proxy, multi-NIC network virtual appliances, an internal load balancer as a next hop, policy-based routes, out-of-band Network Security Integration, and Packet Mirroring to collectors |
Do the arithmetic on those approximations before building a plan. The six midpoints total 100%. Google still prints a tilde on every band, so no exact split exists to memorize. Section 1 is the heaviest band. Section 2 sits next. Sections 3 and 4 share the next band. Section 5 sits next. Section 6 is the lightest band. Any study plan that gives six equal weeks overweights network security and underweights VPC design and implementation.
The logistics come off the certification page. The standard sitting is 2 hours. The format is 50 to 60 multiple choice and multiple select questions. Languages are English and Japanese. The registration fee is 200 USD, and tax where applicable. Delivery is online-proctored from a remote location or onsite-proctored at a testing center. Prerequisites are none. The certification page does not print a Validity period field this pass. Google Cloud Certification Exam Policies and Exam Terms and Conditions say a Professional Certification is valid for two years from the date of issue.
Case studies are not a scored share on this sitting. The certification page and the official exam guide PDF name no companies and no case-study percentage. Do not study a fifth company a dump site invented. Do not carry Professional Cloud Architect case-study habits onto this timer as if they were official here.
Scoring is the part most third-party pages get wrong. The certification page and the exam guide do not publish a numeric passing score, a scaled range, or a percent hedge. Exam Terms and Conditions say that if you pass an Exam, you will receive a digital certificate after Google has validated your score. That is the official pass language. This guide does not invent a 700 mark or a 70 percent story for a vendor that did not publish one.
The same terms page is the source for retakes and for how long the credential lasts. Associate and Professional exams allow a maximum of four attempts in a two year period. After a failed attempt, the wait is 14 days. After a second failed attempt, the wait is 60 days. After a third failed attempt, the wait is 365 days before a fourth attempt. Each attempt requires payment. Passing a Professional exam during renewal extends validity for two years from the date of passing.
Renewal on this title follows the exam path. Professional renewal eligibility on the terms page begins 60 days before expiration. The certification page sends holders to Renewal FAQs for the eligibility window. That page does not publish a shorter 1 hour sitting, a 20 question count, or a 100 USD fee for this title. Do not invent those numbers from a different Google exam. After the eligibility window, the path back is the standard exam.
Two more details change how the sitting is taken. Google may update exam content at any time to reflect changes to Google Cloud technology. The certifications hub says exams are being updated for product updates announced at Google Cloud Next '26, including Gemini Enterprise Agent Platform and Google Cloud's data and analytics stack. The current Professional Cloud Network Engineer guide does not score Gemini Enterprise Agent Platform. It names Vertex AI as a private-access example in section 1.3. The product names that matter on this timer are the names on the current exam guide, not the names on last month's console banner.
What the current outline changed
The exam guide does not publish a Microsoft-style change-log table. The official delta is the set of names the current pages print.
The certification page for this title does not open with a branding-change banner this pass. The exam guide is still the place to review the product names used on the exam. The current guide already says Network Connectivity Center, Private Service Connect, Private NAT, privately used public IP, Cross-Cloud Interconnect, HA VPN over Cloud Interconnect, MACsec, GKE Dataplane V2, GKE Gateway controller, Cloud NGFW Essentials, Standard, and Enterprise, Secure Web Proxy, Adaptive Protection, Google Threat Intelligence, Flow Analyzer, and Network Analyzer.
The certifications hub is more specific about the product wave. Exams are being updated to reflect product updates announced at Google Cloud Next '26, including Gemini Enterprise Agent Platform and Google Cloud's data and analytics stack. The current Professional Cloud Network Engineer guide does not put Gemini Enterprise Agent Platform on a scored section. A study plan that treats that name as a network-engineer extra is studying a different professional exam.
Current product docs have already moved some of those names. The sitting has not finished every move.
| Name on the exam guide | Name on current first-party docs | What that means on the sitting |
|---|---|---|
| Cloud NGFW | Cloud Next Generation Firewall, with Essentials, Standard, and Enterprise tiers | A packet or layer 7 inspection stem is Cloud NGFW, not a leftover VPC-only firewall story |
| VPC firewall rules | Still present as the older per-network control | A migrate-the-rule stem is Cloud NGFW policies, not a reason to ignore VPC firewall rules |
| Network Connectivity Center | NCC overview, with VPC, hybrid, producer, and Gateway spokes | A many-VPC mesh or star stem is Network Connectivity Center, not a pile of peering pairs |
| Private Service Connect | Private Service Connect endpoints, backends, and interfaces | A private consumer IP to a Google API or a published service is Private Service Connect |
| Private NAT | Private NAT for overlapping ranges and NCC spokes | An overlap toward another VPC or an on-premises range is Private NAT, not Public Cloud NAT |
| HA VPN over Cloud Interconnect | Named on the Cloud VPN overview and the Cloud Interconnect overview | Encryption on a VLAN attachment is HA VPN over Cloud Interconnect, not MACsec by itself |
| MACsec | Named on the Cloud Interconnect overview as circuit encryption | Encryption on the physical circuit is MACsec, not an IPsec tunnel |
| GKE Dataplane V2 | GKE Dataplane V2 on the current GKE networking docs | A GKE eBPF dataplane stem is Dataplane V2, not a routes-based cluster |
Validity and renewal changed the calendar around the sitting even when the six section names stayed close. Professional Cloud Network Engineer lasts 2 years on the terms page. Foundational and Associate credentials last 3 years on the same page. Mixing those clocks is how people schedule the wrong renewal door.
Three things follow for anyone holding older material.
The six section names are still the spine. Design, implement, managed services, hybrid, operations, and network security are still the scored map. Notes organized on those six headings are still structurally useful.
The product names inside those headings are in motion. Network Connectivity Center, Private Service Connect, Cloud NGFW, and HA VPN over Cloud Interconnect are the names the exam guide prints. A flashcard that only knows last year's console label, and cannot map it back to the outline, is already off the current PDF.
This sitting has no official case-study PDFs. Time spent on invented company names is time taken from sections 1 and 2.
How a VPC path gets picked
Section 1 is about 21%, the heaviest band. Section 2 is about 20%. Together they are the majority of the sitting. The same habit shows up in hybrid stems and security stems as often as in VPC ones. The skill is small. Name whether the stem is buying one shared host network, a private pair of networks, a hub that can grow, a private consumer IP to a service, or a subnet that must reach Google APIs without an external address.

Virtual Private Cloud (VPC) overview says a VPC network is a global resource made of regional subnets connected by a global wide area network. Networks are logically isolated from each other. Each network implements a distributed virtual firewall. Two implied firewall rules block all incoming connections and allow all outgoing connections. Routes tell instances how to send traffic. Forwarding rules send traffic to a resource based on IP address, protocol, and port. Treating a VPC as a regional island is how section 1.2 is lost. The network is global. The subnet is regional.
Network Service Tiers overview is the first design fork on the exam guide. Premium Tier delivers traffic on Google's backbone. Standard Tier uses regular ISP networks. Premium publishes a 99.99% uptime figure. Standard publishes 99.9%. Global external Application Load Balancers and Cloud CDN require Premium. Cloud VPN gateways require Premium. A stem about the lowest-latency internet path is Premium. A stem about a regional external load balancer that must stay cheaper is Standard. Putting Cloud CDN on Standard is the trap. Cloud CDN is always Premium.
Shared VPC designates a host project and attaches service projects so those projects use subnets in the host network. Shared VPC Admins enable the host and attach the service projects. Service Project Admins receive the Network User role on the whole host or on selected subnets. Projects must sit in the same organization. A project cannot be both a host and a service project at once. Billing for a resource sits on the service project that owns the resource, even when the packet uses the host network. A stem about many application projects that must share one set of subnets, routes, and firewalls is Shared VPC. Flattening every team into one project to make routing easier is the trap when the outline already named Shared VPC and multi-project IAM.
VPC Network Peering connects two VPC networks so resources communicate on internal IPv4 and IPv6. Peering traffic has the same latency, throughput, and availability as traffic inside one VPC. Peering is not transitive. If network A peers with B and A peers with C, B does not reach C through peering. Two auto mode VPC networks cannot peer because both use 10.128.0.0/9. Peering exchanges routes. It does not exchange firewall rules and it does not exchange IAM policies. A stem about two networks that must talk privately, and only those two, is VPC Network Peering. A stem about ten networks that must all reach each other is Network Connectivity Center.
NCC overview is the hub and spoke control. The exam guide names VPC spokes, hybrid spokes, and producer spokes. A VPC spoke exports subnet routes to the hub and imports subnet routes and dynamic routes from the hub. A hybrid spoke is an HA VPN tunnel, a Cloud Interconnect VLAN attachment, or a Router appliance VM. A producer spoke makes a service reached through VPC Network Peering available to the other spokes. Site-to-site data transfer re-advertises dynamic routes among hybrid spokes that sit in one VPC. Classic VPN tunnels are not supported as NCC spokes. A stem about a star or a mesh of many VPCs is Network Connectivity Center. A stem about two VPCs only is still peering unless the stem already asked for a hub that can grow.
Private access is three answers, not one. Private Google Access lets VMs that have only internal IP addresses reach the external IP addresses of Google APIs. You enable it on a subnet. It has no effect on VMs that already have external IPs. Private Service Connect lets consumers use their own internal IP addresses to reach published services or Google APIs without leaving the VPC. Endpoints are consumer-initiated forwarding rules. Backends put a consumer load balancer in front of the service. Interfaces let a producer initiate connections back into the consumer network. Private services access uses the Service Networking API and an allocated range that peers to a Google-managed producer network. Send serverless traffic to a VPC network is the Serverless VPC Access connector the exam guide names next to those three. A stem about a VM without an external IP that must call storage.googleapis.com on Google's API address is Private Google Access. A stem about a private consumer IP you own is Private Service Connect. A stem about an allocated range for a managed service such as Cloud SQL is private services access. Treating those three as one "private Google" story is how section 1.1 is lost.
Routes and Policy-based routes are section 2.2. System-generated routes cover subnet-to-subnet traffic and the default internet route. Custom static routes send selected packets to a next hop you name. Policy-based routes match more than destination, including protocol and source, and they sit in the order the exam guide already named next to network tags and priority. Internal passthrough Network Load Balancers as next hops is how you put a high-availability pair of multi-NIC appliances on the path without pinning one VM. Cloud Router overview is the BGP control plane. Cloud Router does not forward packets. Andromeda forwards packets. Dynamic routing mode is regional or global. Global mode advertises and learns across regions. A stem about a next hop that must survive one appliance failing is an internal load balancer as next hop. A stem about learning on-premises prefixes is Cloud Router. A stem about matching source and protocol, not only destination, is a policy-based route.
GKE networking is section 1.4 and section 2.4. VPC-native clusters use alias IP ranges. That mode is the default for new clusters. Nodes take addresses from the subnet primary range. Pods take addresses from a secondary range. Services take addresses from another secondary range, or from the Google-managed 34.118.224.0/20 range on recent versions. Pod IPs are natively routable in the VPC and through VPC Network Peering. Valid ranges include RFC 1918, non-RFC 1918 private, and privately used public IP. GKE Dataplane V2 is the eBPF dataplane the exam guide names. Customize your network isolation in GKE is the live page for private nodes, private control plane endpoints, and authorized networks. A stem about 900 nodes and 110 Pods per node is a secondary-range sizing problem. A stem about a control plane that must stay off the public internet is a private cluster. A stem about which CIDR may reach that control plane is authorized networks. Building a routes-based cluster because an older lab used one is the trap. New clusters are VPC-native.
Maximum transmission unit is a design bullet in section 1.2 and a hybrid bullet in section 1.3. Cloud Interconnect VLAN attachments support 1440, 1460, 1500, and 8896 bytes. A stem that names jumbo frames on an unencrypted VLAN attachment is 8896. A stem that mixes MTUs across attachments on the same VPC is already the weaker design. Bring your own IP addresses is how you advertise your own public prefixes on Google's network. Cloud NAT overview and Private NAT split internet egress from overlapping-range translation. Public NAT gives private VMs shared external IPs for outbound internet. It does not allow unsolicited inbound connections. Private NAT translates overlapping private ranges toward another VPC, an on-premises network, or another cloud, including Network Connectivity Center spokes. A stem about private VMs that must download updates is Public Cloud NAT. A stem about two RFC 1918 ranges that overlap is Private NAT.
| Control | What the stem is buying | First Google Cloud product | What it does not do well |
|---|---|---|---|
| Shared host | Many projects on one set of subnets | Shared VPC | A pair of independent networks |
| Private pair | Two VPCs that must talk on internal IPs | VPC Network Peering | A transitive mesh |
| Hub | Many VPCs, or VPCs and hybrid, on one control | Network Connectivity Center | A single peering pair |
| Google API from a private VM | Reach Google's API addresses without an external IP | Private Google Access | A consumer-owned VIP |
| Consumer VIP | Your own internal IP to a service or API | Private Service Connect | An allocated Service Networking range |
| Allocated range | A Google-managed producer network such as Cloud SQL | Private services access | A PSC endpoint |
| Serverless path | Cloud Run or Cloud Functions into a VPC | Serverless VPC Access | A GKE Pod range |
| Internet egress | Private VMs that must start outbound connections | Public Cloud NAT | URL filtering |
| Overlap NAT | Two private ranges that collide | Private NAT | Internet egress by itself |
| Appliance hop | Packets that must hit a high-availability NVA | Internal load balancer as next hop | A single static route to one VM |
| GKE Pod IP | Alias ranges that route natively | VPC-native clusters | A routes-based cluster |
Read the constraint the stem is buying. Many application projects on one host network is Shared VPC. Two networks that must talk, and only those two, is VPC Network Peering. Ten networks that must all reach each other is Network Connectivity Center. A VM without an external IP that must call a Google API on Google's address is Private Google Access. A private IP you own in front of that API is Private Service Connect. Two overlapping RFC 1918 ranges are Private NAT. A GKE cluster that must grow Pods without burning static routes is VPC-native.
How load balancers, DNS, and CDN get picked
Section 3 is about 16%. Section 1.1 already asked you to choose a load balancer and a DNS topology during design. Section 3 scores the configuration. The skill is small. Name whether the stem is buying HTTP, TCP proxy, or passthrough, then whether the clients are on the internet or inside the VPC, then whether the backends sit in one region or many.
Choose a load balancer is the official decision page. Choose an Application Load Balancer for HTTP or HTTPS. Choose a proxy Network Load Balancer for TCP proxy load balancing, with optional SSL offload on the external global and classic modes. Choose a passthrough Network Load Balancer when you must preserve the client source IP, avoid proxy overhead, or support UDP, ESP, GRE, or ICMP. External load balancers take internet clients. Internal load balancers take clients in the same VPC, or clients that arrive through VPC Network Peering, Cloud VPN, or Cloud Interconnect. Global and cross-region modes spread backends across regions. Regional modes keep backends, and TLS termination for regional Application Load Balancers, in one region. Proxy load balancers terminate the client connection and open a new one to the backend. Passthrough load balancers leave source, destination, and port unchanged and use direct server return. A stem about HTTPS with URL maps is an Application Load Balancer. A stem about raw TCP that must keep the client IP is a passthrough Network Load Balancer. A stem about jurisdictional TLS termination in one region is a regional Application Load Balancer. A stem about one anycast IP in front of backends in three regions is a global external Application Load Balancer on Premium Tier.
Cloud Load Balancing overview and Network endpoint groups overview are the backend page. Backends include managed instance groups and network endpoint groups. Balancing method, session affinity, serving capacity, URL maps, health checks, and global access are the knobs the exam guide names. Global access on a regional internal forwarding rule lets clients in other regions reach that VIP. About Gateway API and GKE Ingress for Application Load Balancers are the two GKE front doors. The exam guide names both, and it names NEGs next to them. A stem about GKE HTTP routing on Gateway API is the Gateway controller. A stem about the older Ingress object in front of an Application Load Balancer is GKE Ingress. Treating those as one "GKE load balancer" story is how section 3.1 is lost.
Traffic management sits on the Application Load Balancer. Traffic splitting, traffic mirroring, and URL rewrites are the three bullets the exam guide prints. A stem about sending 10 percent of requests to a new backend service is traffic splitting. A stem about copying requests to a shadow service is traffic mirroring. A stem about changing the path before the backend sees it is a URL rewrite. Draining and redirecting those flows during an incident is a section 5.2 skill on the same product.
Cloud CDN overview uses Google's edge to serve cacheable content closer to users. It works with the global external Application Load Balancer or the classic Application Load Balancer. Origins include managed instance groups, Cloud Storage buckets, Cloud Run, internet NEGs, and third-party object storage. The first request is a cache miss. Later requests for the same cache key are cache hits. Invalidation is how you remove cached content before TTL expiry. Cloud CDN is always Premium Tier. A stem about a Cloud Storage bucket behind a global HTTPS load balancer that must serve objects from cache is Cloud CDN. A stem about a regional Standard Tier load balancer is already the wrong front door for CDN.
Cloud DNS overview publishes public zones and private managed zones. A public zone is visible on the internet. A private zone is visible only from VPC networks you authorize. Shared VPC private zones are created in the host project, or they use cross-project binding from a service project. DNS Security Extensions (DNSSEC) overview is managed signing for public zones. Create a forwarding zone and DNS server policies are inbound and outbound forwarding. An inbound server policy lets on-premises resolvers query Cloud DNS through Cloud VPN or Cloud Interconnect. A forwarding zone or an outbound server policy sends VPC queries to a resolver you name. An outbound server policy that points at an alternative name server turns off resolution of Cloud DNS private zones for that VPC. Create a peering zone shares a private zone with another network. Split-horizon DNS is a public zone and a private zone for the same name. Geolocation and failover routing policies are the two Cloud DNS routing policies the exam guide names. A stem about signed public responses is DNSSEC. A stem about on-premises hosts that must resolve a Cloud DNS private zone is inbound forwarding. A stem about VPC VMs that must resolve an on-premises zone is a forwarding zone. A stem about sharing one private zone with a peered VPC is DNS peering. A stem about the same name answering differently inside and outside the VPC is split-horizon.
| Control | What the stem is buying | First Google Cloud product | What it does not replace |
|---|---|---|---|
| HTTP front door | HTTPS, URL maps, or traffic split | Application Load Balancer | A passthrough TCP balancer |
| TCP proxy | TCP with optional SSL offload | Proxy Network Load Balancer | Client source IP preservation |
| Passthrough | Keep client IP, or UDP and ICMP | Passthrough Network Load Balancer | HTTP URL maps |
| Internal VIP | Clients already on the VPC or hybrid path | Internal load balancer | An internet anycast IP |
| Multi-region anycast | One IP, backends in many regions | Global external Application Load Balancer | A regional Standard Tier balancer |
| Regional TLS | Terminate TLS in one jurisdiction | Regional Application Load Balancer | A global anycast front door |
| GKE Gateway | Gateway API HTTP routing | GKE Gateway controller | The older Ingress object |
| GKE Ingress | Ingress to an Application Load Balancer | GKE Ingress controller | Gateway API |
| Cache | Objects served from Google's edge | Cloud CDN | A regional Standard Tier balancer |
| Invalidate | Remove a cached object now | Cloud CDN invalidation | Waiting for TTL |
| Public DNS | Names the internet must resolve | Cloud DNS public zone | A private zone |
| Private DNS | Names only authorized VPCs may resolve | Cloud DNS private zone | A public zone |
| Signed DNS | Authenticated public responses | DNSSEC | An egress URL filter |
| Inbound DNS | On-premises resolvers querying Cloud DNS | Inbound server policy | A peering zone |
| Outbound DNS | VPC VMs querying an on-premises resolver | Forwarding zone | An inbound policy |
| Shared private zone | One private zone visible to another VPC | DNS peering | VPC Network Peering by itself |
Read the constraint. A public checkout page that needs URL maps is a global external Application Load Balancer. A private admin API that must keep the client IP is an internal passthrough Network Load Balancer. A Cloud Storage site that must hit from the edge is Cloud CDN. A corporate name that must resolve only inside the VPC is a Cloud DNS private zone. An on-premises resolver that must see that name is inbound forwarding. Signing that public zone is DNSSEC.
How a hybrid path gets picked
Section 4 is about 16%. Section 1.3 already asked you to design the same path. Section 4 scores the attachment, the tunnel, and the BGP session. The skill is small. Name whether the stem is buying a dedicated circuit, a partner circuit, a cross-cloud circuit, an encrypted internet VPN, or encryption on top of an interconnect.

Cloud Interconnect overview is the family page. Dedicated Interconnect is a direct physical connection between your on-premises network and Google's network. Partner Interconnect reaches Google through a supported service provider. Cross-Cloud Interconnect is a direct physical connection between Google's network and another cloud provider. Partner Cross-Cloud Interconnect uses a supported provider for that same job. Traffic does not traverse the public internet. Internal VPC addresses are reachable without a NAT device. Cloud Interconnect does not encrypt by default. MACsec encrypts the physical circuit between your on-premises router and Google's edge router. HA VPN over Cloud Interconnect adds IPsec on the VLAN attachment. VLAN attachments support MTUs of 1440, 1460, 1500, and 8896 bytes. Reliability options on that page are 99.99% for critical production, 99.9% for non-critical production, and no SLA.
Dedicated Interconnect overview is the colocation product. You meet Google in a facility, present 10-Gbps, 100-Gbps, or 400-Gbps circuits, and run LACP, 802.1Q, and EBGP. Google sends a Letter of Authorization and Connecting Facility Assignment. You provision the cross-connect, test the circuit, then create VLAN attachments and associate each attachment with a Cloud Router. Critical production 99.99% availability needs at least four Dedicated Interconnect connections, two in one metropolitan area and two in another, with the pair in each metro placed in different edge availability domains. Non-critical 99.9% needs at least two connections in one metro and two edge availability domains. A stem about the highest bandwidth and a facility you can reach is Dedicated Interconnect. A stem about 99.99% is four attachments across two metros, not two circuits in one building.
Partner Interconnect overview is the service-provider product. Use it when your data center cannot reach a Dedicated Interconnect facility, or when you do not need an entire 10-Gbps circuit. Layer 2 means you configure BGP between your on-premises router and Cloud Router. Layer 3 means the provider establishes BGP and you do not configure BGP on your local router. Layer 3 connections can be pre-activated so traffic flows as soon as the provider configures the attachment. Layer 3 cannot pass MED values through the provider autonomous system. You cannot set route priorities the way you can on Layer 2. A 99.99% Partner topology still needs four VLAN attachments across two metros. A stem about a site that cannot reach a Google colocation is Partner Interconnect. A stem about who runs BGP is Layer 2 versus Layer 3. Treating those layers as synonyms is how section 4.1 is lost.
Cloud VPN overview encrypts traffic between private networks with IPsec. It does not route to the public internet. HA VPN is two interfaces, dynamic BGP routing only, and a 99.99% SLA for most topologies. It supports IPv6. Classic VPN is one interface, static routing that is policy-based or route-based, a 99.9% SLA, and no IPv6. HA VPN can connect an on-premises gateway, another Cloud VPN, or another VPC. HA VPN over Cloud Interconnect puts those IPsec tunnels on a VLAN attachment so traffic never traverses the public internet and still receives encryption. Partner Interconnect often needs that extra IPsec hop to meet a compliance rule when a third-party provider sits on the path. A stem about encryption over the internet is HA VPN. A stem about encryption on an interconnect is HA VPN over Cloud Interconnect. A stem about encrypting the physical circuit itself is MACsec. A stem about a single static tunnel is Classic VPN. Building Classic VPN because an older lab used target-vpn-gateway is the trap. The outline still names Classic VPN. HA VPN is the current high-availability answer.
Cloud Router overview is required for Dedicated Interconnect, Partner Interconnect, Cross-Cloud Interconnect, HA VPN, and Router appliances. It is optional for Classic VPN. Cloud Router manages BGP. It does not forward packets. Bidirectional Forwarding Detection, MD5 authentication, custom advertised routes, and custom learned routes are the knobs the exam guide names. Legacy versus standard best path selection is a VPC-level choice on that same outline. IPv6 route exchange uses IPv6 BGP or multiprotocol BGP on an IPv4 session. Classic VPN, Router appliances, and Cross-Cloud Interconnect VLAN attachments do not support IPv6 BGP peering. A stem about a link that must fail over faster than BGP hold time is BFD. A stem about advertising a summary instead of every subnet is a custom advertised route. A stem about installing a prefix the peer never sent is a custom learned route.
Direct Peering overview connects your network to Google for Google Workspace and public Google APIs. It is not a replacement for Cloud Interconnect into a VPC. The exam guide pairs it with Verified Peering Provider. A stem about reaching Google public services over a private peering is Direct Peering. A stem about reaching RFC 1918 addresses in a VPC is Cloud Interconnect or Cloud VPN.
Network Connectivity Center returns in section 4.4 as hybrid spokes. Create hybrid spokes for VPN tunnels and VLAN attachments. Enable site-to-site data transfer when two on-premises sites must use Google's network as the WAN. Create router appliances when a third-party device must speak BGP through Cloud Router. Transitivity problems that peering cannot solve are the reason the hub exists. A stem about New York, Sydney, and Tokyo exchanging prefixes over Google's backbone is site-to-site data transfer. A stem about an SD-WAN appliance is a Router appliance spoke.
| Control | What the stem is buying | First Google Cloud product | What it does not replace |
|---|---|---|---|
| Dedicated circuit | Direct fiber in a Google colocation | Dedicated Interconnect | A software VPN |
| Partner circuit | A provider that already meets Google | Partner Interconnect | Layer 2 and Layer 3 as one answer |
| Cross-cloud circuit | A physical path to another cloud | Cross-Cloud Interconnect | HA VPN to that cloud |
| Internet IPsec | Encrypted path over the public internet | HA VPN | A Dedicated Interconnect |
| Static VPN | One interface, policy-based or route-based | Classic VPN | A 99.99% SLA |
| Circuit encrypt | Encrypt the physical interconnect | MACsec | An IPsec tunnel |
| Attachment encrypt | IPsec on a VLAN attachment | HA VPN over Cloud Interconnect | MACsec by itself |
| BGP control | Advertise and learn prefixes | Cloud Router | Packet forwarding |
| Fast failover | Detect a dead peer before hold time | BFD | A second Cloud Router by itself |
| Public Google peek | Reach Google public APIs off a private peer | Direct Peering | RFC 1918 in a VPC |
| Site to site | Two on-premises sites over Google's WAN | NCC site-to-site data transfer | VPC Network Peering |
| Appliance BGP | A third-party router in the VPC | Router appliance | Classic VPN |
Read the constraint. A factory that can reach a Google colocation and needs 100 Gbps is Dedicated Interconnect. A branch that can only reach a carrier is Partner Interconnect. A workload that already lives in another cloud and needs a private physical path is Cross-Cloud Interconnect. A backup path that must encrypt over the internet is HA VPN. A regulator that requires encryption on the interconnect is HA VPN over Cloud Interconnect or MACsec, and the stem tells you which layer. Two sites that must use Google as the WAN are Network Connectivity Center hybrid spokes with site-to-site data transfer.
How operations and network security get picked
Section 5 is about 14%. Section 6 is about 13%. Together they ask the same follow-up after the path, the balancer, and the circuit are already chosen. Name whether the stem is buying a log, a simulated path, a packet copy, an edge WAF, a distributed firewall, or an egress proxy.

Network Intelligence Center overview is the operations console. Connectivity Tests overview simulates the expected forwarding path through the VPC, Cloud VPN, or a VLAN attachment, and it can send live packets for latency and loss. Network Topology overview visualizes throughput and hybrid paths. Performance Dashboard overview shows packet loss and latency for the Google network and for your project. Firewall Insights overview finds unused or overly permissive rules. Network Analyzer overview watches configuration continuously and correlates failures with recent changes. Flow Analyzer overview reads VPC Flow Logs at 5-tuple granularity without writing SQL. VPC Flow Logs records the flows. Packet Mirroring copies packets to an inspection target. A stem about "why can these two IPs not talk" is Connectivity Tests. A stem about Google-wide packet loss is Performance Dashboard. A stem about a rule that never hits is Firewall Insights. A stem about bytes between two VMs is VPC Flow Logs or Flow Analyzer. A stem about full packets for a sensor is Packet Mirroring. Naming Cloud Logging for every one of those is how the operations band is wasted.
Section 5.1 still needs the product logs. Enable Cloud Logging on Cloud VPN, Cloud Router, VPC Service Controls, Cloud NGFW, Cloud DNS, Cloud NAT, and Network Connectivity Center. Watch metrics on Cloud VPN, Cloud Interconnect and VLAN attachments, Cloud Router, load balancers, Google Cloud Armor, and Cloud NAT. Section 5.2 is the incident. Drain and redirect Application Load Balancer traffic. Troubleshoot VPN, Interconnect, and Cloud Router BGP. Use VPC Flow Logs, firewall logs, and Packet Mirroring together when a simulated path is not enough.
Cloud Armor overview is the edge. Security policies are ordered rules applied to requests destined for a protected resource. Preconfigured WAF rules help mitigate OWASP Top 10 risks, including SQL injection, cross-site scripting, and remote file inclusion. Always-on Layer 3 and Layer 4 DDoS protection sits on supported load balancers. Layer 7 HTTP flood protection needs a configured policy. Adaptive Protection and Google Threat Intelligence sit on Cloud Armor Enterprise. Edge policies apply before a Cloud CDN lookup. Backend policies apply on cache misses and dynamic content. Policies attach at the edge, close to the traffic source, so unwanted requests never consume the VPC. A stem about SQLi on a public HTTPS load balancer is Google Cloud Armor. A stem about east-west traffic between two private GKE Services is Cloud NGFW.
Cloud NGFW overview is the distributed, stateful firewall for Google Cloud workloads. It inspects north-south traffic that enters or leaves a VPC and east-west traffic among resources inside VPC networks. Controls sit at Layer 3, Layer 4, and Layer 7. Essentials is the foundational tier for IP ranges, ports, and protocols. Standard adds fully qualified domain names and threat intelligence. Enterprise adds URL filtering and intrusion detection and prevention. Hierarchical, global, and regional firewall policies exist. Firewall policies and rules is the page for those policy objects. VPC firewall rules are the older per-network control. The exam guide asks you to migrate those rules to Cloud NGFW policies and to read the effective rule set when hierarchical policies apply. Micro-segmentation uses metadata, secure tags, service accounts, and network tags. A stem about allowing TCP 443 from one subnet to another is Cloud NGFW. A stem about inspecting HTTP hosts and blocking a URL category is Cloud NGFW Enterprise. Putting that URL filter on Google Cloud Armor because both products say "web" is the trap when the traffic never hits a load balancer.
Secure Web Proxy overview is the explicit egress proxy for internet-bound traffic. The exam guide names it next to Public Cloud NAT. Cloud NAT translates outbound connections. Cloud NAT does not inspect URLs. Secure Web Proxy does. Automatic or manual Cloud NAT IP assignment and static or dynamic port allocation are the NAT knobs in section 6.3. A stem about private VMs that must reach the internet is Cloud NAT. A stem about those same VMs reaching only approved URLs is Secure Web Proxy.
Overview of VPC Service Controls builds service perimeters around Google Cloud services so data in Cloud Storage, BigQuery, and similar APIs cannot leave an authorized boundary. That is a different control from a VPC firewall rule. A firewall rule decides which packets move. A service perimeter decides which Google APIs a project may call and which identities may take data out. A stem about a compromised VM copying a bucket to an unauthorized project is VPC Service Controls. A stem about that VM opening TCP 22 from the internet is Cloud NGFW.
Multi-NIC appliances close section 6.4. Create VMs with multiple network interfaces is the VM shape. An internal load balancer as next hop keeps that pair highly available. Policy-based routes steer selected flows to the pair. Out-of-band Network Security Integration and Packet Mirroring send copies to self-managed collectors without putting the appliance in line. A stem about inline inspection between two VPCs is a multi-NIC appliance and an internal load balancer next hop. A stem about a copy of the packet for a sensor is Packet Mirroring.
| Control | What the stem is buying | First Google Cloud product | What it does not replace |
|---|---|---|---|
| Simulated path | Why two endpoints cannot talk | Connectivity Tests | A packet capture |
| Topology | A picture of throughput and hybrid links | Network Topology | A firewall recommendation |
| Loss and latency | Google-wide or project packet loss | Performance Dashboard | A flow record |
| Rule hygiene | A firewall rule that never hits | Firewall Insights | A WAF signature |
| Config warning | A recent change that broke a path | Network Analyzer | A live ping |
| 5-tuple | Bytes between IPs and ports | Flow Analyzer | Full packet payloads |
| Flow record | The log those bytes came from | VPC Flow Logs | A packet copy |
| Packet copy | Full packets to a collector | Packet Mirroring | A flow record |
| Edge WAF | SQLi, XSS, or DDoS on a public load balancer | Google Cloud Armor | East-west micro-segmentation |
| Packet filter | Allow or deny by IP, port, or protocol | Cloud NGFW | A WAF on a public load balancer |
| Layer 7 inspect | URL category or intrusion prevention inside the VPC | Cloud NGFW Enterprise | Identity-Aware Proxy |
| Egress proxy | Approved URLs for private VMs | Secure Web Proxy | Cloud NAT by itself |
| Outbound NAT | Private VMs that must start internet connections | Public Cloud NAT | URL filtering |
| Service perimeter | Stop data leaving Google APIs | VPC Service Controls | A VPC firewall rule |
| Inline NVA | Inter-VPC traffic that must hit an appliance | Multi-NIC VM and ILB next hop | Packet Mirroring |
Read the constraint. A public checkout page that must reject SQLi is Google Cloud Armor. A subnet that must talk to another subnet on 443 is Cloud NGFW. A private VM that must reach only approved URLs is Secure Web Proxy. A bucket that must not leave the perimeter is VPC Service Controls. Two IPs that should talk and do not is Connectivity Tests. A sensor that needs payloads is Packet Mirroring. Naming Cloud NGFW for every one of those is how the security band is wasted.
How to study the current blueprint
Order the weeks by the weight bands, not by the order the products appear in a catalog.
Week 1. VPC design, the band near 21%. Create a custom-mode VPC with two regional subnets and write down that the network is global and the subnet is regional. Compare Premium and Standard on one external IP. Create a Shared VPC host project, attach one service project, and grant compute.networkUser on one subnet only. Peer two custom-mode VPCs and confirm that a third VPC does not arrive through transitivity. Create a Network Connectivity Center hub with two VPC spokes and compare that mesh with the peering pair. Enable Private Google Access on one subnet and call a Google API from a VM that has no external IP. Create a Private Service Connect endpoint to a Google API and write down that this VIP is yours. Allocate a private services access range. Size a GKE primary range and a Pod secondary range for a 50-node cluster. Write down the MTU you would pick for a VLAN attachment.
Week 2. VPC implementation, the band near 20%. Expand a subnet range after creation. Create a Cloud NGFW policy that allows 443 between two subnets and denies the rest. Create a static route and a policy-based route and write down which packets each one matches. Put an internal passthrough Network Load Balancer in front of two multi-NIC VMs and use it as a next hop. Create a Cloud Router and switch the VPC between regional and global dynamic routing. Export a custom route over VPC Network Peering. Create a VPC-native GKE cluster on Shared VPC, mark the control plane private, add an authorized network, and enable Dataplane V2. Add a second Pod range. Compare kube-dns, Cloud DNS, and a local DNS cache. Create a VPC Service Controls perimeter around a Cloud Storage project and try an unauthorized copy.
Week 3. Managed services near 16%, hybrid near 16%. Create a global external Application Load Balancer with a URL map and a health check. Create an internal passthrough Network Load Balancer and enable global access. Attach Cloud CDN to a Cloud Storage backend, hit an object twice, then invalidate it. Create a Cloud DNS public zone and a private zone for the same name. Enable DNSSEC on the public zone. Create a forwarding zone and a peering zone. Sketch Dedicated Interconnect versus Partner Interconnect versus Cross-Cloud Interconnect on paper and name which one the stem is buying. Sketch HA VPN versus Classic VPN and write down that Classic VPN is static and 99.9%. Sketch MACsec versus HA VPN over Cloud Interconnect. Create an HA VPN to a second VPC if you can, or walk the HA VPN topologies page if you cannot. Create a Cloud Router BGP session and add a custom advertised route. Write down the 99.99% topology, four attachments, two metros, two edge availability domains.
Week 4. Operations near 14%, network security near 13%, and a full review. Run a Connectivity Test between two VMs and read the simulated path. Open Network Topology and Performance Dashboard. Enable VPC Flow Logs and open Flow Analyzer. Open Firewall Insights and Network Analyzer. Attach a Cloud Armor security policy with a preconfigured WAF rule to the public load balancer from week 3. Compare Cloud NGFW Essentials, Standard, and Enterprise on paper and add a layer 7 inspection rule if you can enable Enterprise. Create Cloud NAT for a private subnet, then compare that path with Secure Web Proxy. Place a Packet Mirroring policy toward a collector. Then sit with the exam guide and, for each bullet, name the product, the path, and the constraint that would have forced that product.
Take any official sample questions the certification page still mentions and walk the exam tutorial at least once before using this outline against a clock. The sample set exists so the question format costs nothing on the timer. This guide does not reprint those items.
Traps that look like easy elimination
Network items rarely give one plausible answer and three absurd ones. They give two paths that both sound correct and one detail that picks between them.
- There is no prerequisite certification. Recommended experience is still 3 or more years, including 1 or more years designing and managing solutions using Google Cloud. Showing up with only vocabulary from Cloud Digital Leader is how sections 1 and 2 are lost.
- The standard sitting is 50 to 60 questions in 2 hours. Notes that quote a 40 to 50 question professional sitting are quoting a different exam.
- Google does not publish a numeric passing score on the certification page or the exam guide. A third-party 700 or 70 percent figure is not official language for this sitting.
- This sitting has no official case-study PDFs. A company name that does not appear on the exam guide is not part of the outline.
- Shared VPC is one host network for many projects. VPC Network Peering is a private link between two networks and is not transitive. Network Connectivity Center is the hub that can grow to a mesh or a star.
- Private Google Access, Private Service Connect, and private services access are three answers. A VM without an external IP that must use Google's API address is Private Google Access. A consumer-owned VIP is Private Service Connect. An allocated Service Networking range is private services access.
- Public Cloud NAT translates internet egress. Private NAT translates overlapping private ranges. Secure Web Proxy inspects egress URLs. Those are three answers.
- Premium Tier is Google's backbone and is required for global external Application Load Balancers, Cloud CDN, and Cloud VPN. Standard Tier is the cheaper regional internet path.
- An Application Load Balancer is HTTP. A proxy Network Load Balancer is TCP proxy. A passthrough Network Load Balancer keeps the client IP and can carry UDP. Those are three answers.
- HA VPN is two interfaces, BGP, and a 99.99% SLA for most topologies. Classic VPN is one interface, static routing, and a 99.9% SLA.
- Dedicated Interconnect is a colocation circuit. Partner Interconnect is a provider circuit, and Layer 2 versus Layer 3 decides who runs BGP. Cross-Cloud Interconnect is a physical path to another cloud.
- MACsec encrypts the physical circuit. HA VPN over Cloud Interconnect encrypts the VLAN attachment. Cloud Interconnect does not encrypt by default.
- A 99.99% interconnect topology is four attachments across two metros and two edge availability domains, not two circuits in one building.
- Cloud Router speaks BGP. It does not forward packets.
- Cloud NGFW filters packets and can inspect layer 7 inside the VPC. Google Cloud Armor is the edge WAF and DDoS control on a load balancer. VPC Service Controls protect Google APIs from exfiltration. Those are three answers.
- Connectivity Tests simulate a path. Flow Analyzer reads VPC Flow Logs. Packet Mirroring copies payloads. Performance Dashboard reports loss and latency. Those are four answers.
- Gemini Enterprise Agent Platform is a Next '26 hub theme and a Professional Cloud Security Engineer product. It is not a scored name on this exam guide. Vertex AI appears here as a private-access example.
- Professional Cloud Architect case studies are not this exam. Professional Cloud Security Engineer identity and key stems are not this exam. Professional Cloud DevOps Engineer pipelines are not this exam. Professional Data Engineer warehouses are not this exam. Associate Cloud Engineer operator clicks are the floor, not the sitting.
If deleting the scenario still lets you pick the answer from the service name, the question is easier than the live exam.
How this maps to CloudFluently
Start with the official material. The Professional Cloud Network Engineer certification page carries the audience profile, the 2 hour timer, the 50 to 60 question format, the 200 USD fee, and the recommended experience. The Professional Cloud Network Engineer exam guide carries the six sections and the product names. Exam Terms and Conditions explain what it means to pass an Exam, how long a Professional Certification lasts, and the 14 day, 60 day, and 365 day retake waits.
Professional Cloud Network Engineer sits on top of Google Cloud vocabulary and Google Cloud operations, and that ground is already live here. Shared responsibility, product families, and the idea of a cloud bill are the Cloud Digital Leader study notes. Projects, IAM, Compute Engine, Cloud Storage, VPC networks, and the operator form of Cloud Monitoring and Cloud Logging are the Associate Cloud Engineer study notes. The Associate Cloud Engineer exam guide is the operator companion.
The architect reading of a VPC or an interconnect, when the stem is still a solution recommendation rather than a network control, is the Professional Cloud Architect exam guide. The security reading of Cloud NGFW, Google Cloud Armor, Secure Web Proxy, or VPC Service Controls, when the stem is an identity, a key, or a finding rather than a packet path, is the Professional Cloud Security Engineer exam guide. The delivery reading of a load balancer, when the stem is a promotion sequence rather than a URL map, is the Professional Cloud DevOps Engineer exam guide. The warehouse reading of Private Service Connect, when the stem is a pipeline or a reservation rather than a private API path, is the Professional Data Engineer exam guide.
Work those until the vocabulary, the operator controls, and the neighboring professional habits are automatic, then use this page and the official exam guide for the network-only skills: the path, the balancer, the circuit, and the control that holds them.
What is the passing score for Professional Cloud Network Engineer? Google does not publish a numeric passing score on the certification page or the exam guide. Exam Terms and Conditions say that if you pass an Exam, you receive a digital certificate after Google has validated your score.
How long is the exam and how many questions are there? The standard sitting is 2 hours with 50 to 60 multiple choice and multiple select questions.
Does this exam use case studies? The certification page and the official exam guide do not publish case studies for this sitting. Study the six sections and the named products.
Is there a prerequisite? No. Google recommends 3 or more years of industry experience, including 1 or more years designing and managing solutions using Google Cloud.
How long does the certification last? A Professional Certification is valid for two years from the date of issue. Renewal is the applicable Exam during the professional eligibility window, which the terms page starts 60 days before expiration. Passing that Exam extends validity for two years from the date of passing.
Can I retake it if I fail? Associate and Professional exams allow four attempts in two years. The waits are 14 days after the first fail, 60 days after the second, and 365 days after the third. Each attempt is paid.
What changed on the current outline? The current guide already names Network Connectivity Center, Private Service Connect, Private NAT, Cross-Cloud Interconnect, HA VPN over Cloud Interconnect, MACsec, GKE Dataplane V2, Cloud NGFW tiers, Secure Web Proxy, Adaptive Protection, Flow Analyzer, and Network Analyzer. The certifications hub points at Google Cloud Next '26 product updates. The product names that matter are the names on the current exam guide.
Which section is heaviest? Designing and planning a Google Cloud VPC network is about 21%. Implementing a VPC network is about 20%. Configuring managed network services is about 16%. Configuring hybrid and multicloud interconnectivity is about 16%. Managing, monitoring, and troubleshooting network operations is about 14%. Configuring a cloud network security solution is about 13%.
Does Google publish a 700 or 70 percent pass mark? No. That figure is not on the certification page, the exam guide, or the terms page opened for this guide.
How does this exam relate to Associate Cloud Engineer, Professional Cloud Architect, and Professional Cloud Security Engineer? Cloud Digital Leader scores vocabulary. Associate Cloud Engineer scores the operator controls. Professional Cloud Architect scores the solution recommendation. Professional Cloud Security Engineer scores the identity, the key, and the finding. Professional Cloud DevOps Engineer scores the pipeline stage. Professional Data Engineer scores the data platform. Professional Cloud Network Engineer scores the path, the balancer, the circuit, and the network control. The official outline is the Professional Cloud Network Engineer exam guide. Use Google for the task statements. Use this page for how those statements get picked, what the current names are, and how to sequence the blueprint.
