Google Cloud Professional Cloud Network EngineerStudy guide
The professional certification for designing, implementing, and operating VPC, routing, load balancing, hybrid connectivity, and network security (Professional Cloud Network Engineer).
About Google Cloud Professional Cloud Network Engineer (GCP-PCN)
Google Cloud Professional Cloud Network Engineer (GCP-PCN) is a Professional / Expert-level certification from Google Cloud. This page organizes the exam scope into a 6-chapter, 12-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."
Exam domains (approximate weighting)
- Designing and planning a Google Cloud VPC network~21%
- Implementing a VPC network~20%
- Configuring managed network services~16%
- Configuring and implementing hybrid and multicloud network interconnectivity~16%
- Managing, monitoring, and troubleshooting network operations~14%
- Configuring, implementing, and managing a cloud network security solution~13%
Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.
Official exam information: https://cloud.google.com/learn/certification/cloud-network-engineer
1Designing and planning a Google Cloud VPC network
- 1.1Overall network design and VPC design
Understand network tiers (Premium/Standard), high availability/failover/DR/scale, DNS topology, load balancer selection, Shared VPC vs standalone, VPC peering and Network Connectivity Center, IP address management (subnets/IPv6/PUPI/non-RFC1918/Private NAT), global/regional dynamic routing, MTU, and IAM roles suited to network designs.
- 1.2Hybrid/multicloud and GKE design
Understand hybrid connectivity (Dedicated/Partner Interconnect, Cloud VPN, SD-WAN), multicloud connectivity (Cloud VPN, Cross-Cloud Interconnect), Direct Peering vs Verified Peering Provider, cross-region HA/DR, hybrid DNS topology (forwarding/inbound policies/DNS peering), interconnect encryption (MACsec/HA VPN over Interconnect), and GKE network design (VPC-native, secondary ranges, private clusters, control-plane access).
2Implementing a VPC network
- 2.1Configuring VPCs and routing
Understand creating VPC resources (networks/subnets/firewall rules or policies), VPC Network Peering, Shared VPC creation and sharing subnets with service projects with IAM permissions, Private Google Access, VPC Service Controls perimeters, expanding subnet ranges, static/dynamic routing (Cloud Router), route priority and network tags, internal LB as a next hop, and policy-based routing.
- 2.2Network Connectivity Center and GKE clusters
Understand Network Connectivity Center spoke types (VPC/hybrid/producer), topologies (star/hub-and-spoke/mesh), Private NAT and PSC propagation, CIDR filters, VPC-native clusters (alias IPs), clusters with Shared VPC, private clusters and control-plane endpoints, authorized networks, DNS-based endpoints, Dataplane V2, SNAT/IP masquerade, network policies, and Pod/Service ranges.
3Configuring managed network services
- 3.1Load balancing
Understand load balancer selection (internal/external, regional/global, application/proxy/passthrough), backend services and autoscaling (NEGs/managed instance groups), balancing mode/session affinity/serving capacity/URL maps/health checks/global access, GKE load balancing (Gateway/Ingress controllers, NEGs), and Application Load Balancer traffic management (splitting/mirroring/URL rewrites).
- 3.2Cloud CDN and Cloud DNS
Understand Cloud CDN (supported origins = MIG/Cloud Storage buckets/Cloud Run, external backends (internet NEGs)/third-party storage, cache invalidation) and Cloud DNS (zones/records, migration, routing policies (geolocation/failover), DNSSEC, self-hosted DNS integration (forwarding/server policies), public/private zones and split-horizon, cross-project binding/DNS peering, external-DNS for GKE).
4Configuring and implementing hybrid and multicloud network interconnectivity
- 4.1Cloud Interconnect and IPSec VPN
Understand Dedicated/Partner/Cross-Cloud Interconnect connections and VLAN attachments, layer-2 vs layer-3 differences, HA VPN over Cloud Interconnect, 99.9%/99.99% SLA topologies, site-to-site IPSec VPN (HA VPN to on-prem/to other VPCs, Classic VPN route-based/policy-based), and encryption options such as MACsec.
- 4.2Cloud Router and hybrid NCC
Understand Cloud Router BGP attributes (ASN, route priority/MED, link-local addresses, authentication), Bidirectional Forwarding Detection (BFD), custom-advertised/learned routes, VPC legacy/standard best-path selection, Network Connectivity Center hybrid spokes (VPN/VLAN attachments), site-to-site data transfer, router appliances (RAs), and solving transitivity issues.
5Managing, monitoring, and troubleshooting network operations
- 5.1Logging/monitoring and connectivity troubleshooting
Understand logging of network components with Google Cloud Observability (Cloud VPN/Cloud Router/VPC Service Controls/Cloud NGFW/Firewall Insights/VPC Flow Logs/Cloud DNS/Cloud NAT/Network Connectivity Center), monitoring networking metrics, draining/redirecting traffic with the Application Load Balancer, troubleshooting VPN/Interconnect/Cloud Router BGP, and investigating with VPC Flow Logs/firewall logs/Packet Mirroring.
- 5.2Network Intelligence Center
Understand monitoring/troubleshooting with Network Intelligence Center: Network Topology (visualize throughput and traffic flows), Connectivity Tests (diagnose route/firewall misconfigurations), Performance Dashboard (packet loss and latency: Google-wide/project-scoped), Firewall Insights (monitor/improve rules), Network Analyzer (auto-detect failures/suboptimal configs/utilization warnings), and Flow Analyzer (evaluate traffic via VPC Flow Logs).
6Configuring, implementing, and managing a cloud network security solution
- 6.1Cloud Armor and Cloud NGFW / VPC firewall
Understand Google Cloud Armor policies (edge/backend security policies, WAF (SQLi/XSS/RFI), advanced network DDoS and Adaptive Protection, rate limiting, bot management, Threat Intelligence) and Cloud NGFW/VPC firewall rules (firewall strategy, hierarchical firewall, effective policy, L7 inspection (NGFW Enterprise), migration from VPC rules, rule criteria (priority/protocol/direction/source/destination), firewall logging, micro-segmentation, NGFW tiers (Essentials/Standard/Enterprise)).
- 6.2Cloud NAT, Secure Web Proxy, and NVA / Packet Mirroring
Understand public Cloud NAT IP addressing (automatic/manual allocation) and static/dynamic port allocation, controlling egress with Secure Web Proxy, self-managed network virtual appliances (multi-NIC VMs/NGFW appliances) with an internal LB as next hop for HA routing, policy-based routes for HA multi-NIC VMs, out-of-band Network Security Integration, and Packet Mirroring to self-managed collectors.

