Google Associate Cloud Engineer exam dumps

Google Associate Cloud Engineer practice question 156 of 375

Associate Cloud Engineer. Free level, Google Cloud. Free question with the correct answer and a full explanation.

Google Associate Cloud Engineer Question 156

Select 3Google Cloud Platform

You are tasked with setting up a secure network for a new application deployment on Google Cloud Platform. The application needs to receive HTTP requests from the internet but should only allow SSH access from a specific internal IP range for management purposes. Which of the following steps would you take to configure the appropriate ingress and egress firewall rules in Google Cloud?

  1. A

    Create an ingress rule allowing HTTP traffic from 0.0.0.0/0 to the application server.

  2. B

    Create an ingress rule allowing SSH traffic from 0.0.0.0/0 to the application server.

  3. C

    Create an ingress rule allowing SSH traffic from the specified internal IP range to the application server.

  4. D

    Create an egress rule allowing all outbound traffic to 0.0.0.0/0.

  5. E

    Create an egress rule denying all outbound traffic by default.

Show answer and explanation

Correct answers: A, C, D

Explanation

To securely configure ingress and egress firewall rules on Google Cloud Platform, it is important to allow only necessary traffic while restricting access from potentially harmful sources. Allowing HTTP traffic from the internet and SSH from a specific internal IP range ensures that the application can function and be managed securely. Permitting all outbound traffic is common to avoid restrictions on necessary server communications.

  • A. Correct.

    This option is correct as it allows HTTP traffic from any source to reach the application server, which is necessary for receiving requests from the internet.

  • B. Incorrect.

    This option is incorrect because it allows SSH access from any IP, which is not secure. SSH access should be restricted to a specific internal IP range.

  • C. Correct.

    This option is correct as it restricts SSH access to only the specified internal IP range, enhancing security for management access.

  • D. Correct.

    This option is correct as it allows the application server to communicate with any external service, which is typically necessary for general internet access.

  • E. Incorrect.

    This option is incorrect because denying all outbound traffic could prevent necessary communication from the application server to the internet or other services.

Timed practice exam

Take a Google Associate Cloud Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam