Explain VPC networks and firewall rules in GCP.
Assesses fundamental understanding of Google Cloud conventions, runtime behavior, and memory/performance considerations.
Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.
A GCP VPC is a global, software-defined network. Subnets are regional, and instances in different regions can communicate over the internal network.
- VPC networks come in auto mode, with one subnet per region, or custom mode. Custom is recommended for control.
- Subnets have a primary CIDR and optional secondary ranges for GKE pods and services.
- Firewall rules are stateful, applied at the VPC level, and use priorities. They target instances by network tags or service accounts.
- Rules define direction, protocol, ports, source and destination ranges, and action. Default rules allow internal traffic and deny ingress from the internet.
gcloud compute firewall-rules create allow-https \
--network=my-vpc --allow=tcp:443 \
--source-ranges=0.0.0.0/0 --target-tags=web
Use hierarchical firewall policies for organisation-wide rules and Shared VPC to centralise networking across projects.
Candidate Response Strategy & Interview Tips
- Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
- Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
- Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
- Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.