Memory hook: Choose protocol, reach and failover scope.
Must remember
Choose load balancing by protocol, external/internal reach, proxy/passthrough behavior and regional/global availability. Application load balancers route HTTP/S; network load balancers serve supported transport-level needs. Backend services, health checks and firewall permissions must agree; a healthy VM does not imply a health-check path is allowed.
Global versus regional resources affect failover and traffic locality. Premium and Standard Network Service Tiers use different network paths and support different product combinations. Check the actual load-balancer type rather than assuming every configuration is global or supports every tier.
Cloud CDN caches eligible content at the edge; cache keys, TTLs and origin protection determine behavior. Cloud Armor applies supported edge/backend security policies. Neither removes the need for secure application authorization or correct cache separation between users.
HA VPN supplies encrypted hybrid tunnels; Cloud Interconnect provides private connectivity with dedicated/partner options. Encryption requirements must be addressed explicitly. Cloud Router manages dynamic BGP route exchange for supported connectivity; it is not itself the data-plane router carrying every packet. Plan redundancy on both provider and on-premises sides.
Cloud DNS public zones publish public records; private zones serve authorized networks. Forwarding and peering zones support hybrid and cross-network resolution patterns. Names resolving correctly does not establish packet reachability. Use split-horizon designs deliberately and avoid forwarding loops.
Reserve static internal/external IPs where a stable endpoint is required. Review health-check sources, firewall rules, backend serving ports, certificates, routing and DNS TTL during migrations. Switching a DNS record does not immediately expire every existing cache or connection.
Review details
For DNS, A/AAAA return IPv4/IPv6 addresses, CNAME aliases a name, MX chooses mail exchangers, TXT carries text data, and NS delegates authority. Public zone creation must be paired with registrar/parent delegation; private zones require authorized networks. DNSSEC authenticates signed answers but does not encrypt queries. TTL controls cache freshness, not a guarantee that every active client connection immediately changes.
For a load-balancer failure, test frontend reachability → selected URL map/backend service → backend health → health-check/data-plane firewall allowance → serving port/application. A proxy load balancer and a passthrough load balancer expose different source-connection behavior; select the precise product before designing source-IP controls.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Private on-premises connectivity | Interconnect with explicit resilience and encryption design. |
| Encrypted hybrid tunnel | HA VPN with redundant BGP/tunnel topology. |
| HTTP host/path routing | Suitable Application Load Balancer configuration. |
Traps
- Cloud Router exchanges routes; it is not the packet-forwarding appliance.
- Private connectivity does not automatically mean encrypted connectivity.
Active recall
1. What chooses between application and network load balancing?
Protocol and required routing/proxy behavior, alongside reach and scope.
2. Why can all backends appear unhealthy?
The health-check path, port or firewall can be wrong even if the application runs.
3. What does Cloud Router do?
Dynamic BGP route management for supported services.
4. Public versus private DNS zone?
Public zones answer public DNS; private zones are visible to authorized network contexts.
5. Why plan DNS TTL before cutover?
Cached old answers can delay traffic movement after a record change.