Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 19 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 19

Select 3Google Cloud Platform

Your organization is hosting a public-facing web application on Google Cloud using a global HTTP(S) Load Balancer. To meet strict security and data exfiltration prevention requirements, you must ensure that only traffic originating from trusted IP ranges can reach the backend services, and any unauthorized data exfiltration attempts are blocked. What steps should you take to achieve this?

  1. A

    Configure a Cloud Armor security policy with allow rules for the trusted IP ranges and attach it to the Load Balancer.

  2. B

    Enable VPC Service Controls and define a service perimeter around the backend services.

  3. C

    Use a Cloud NAT gateway to restrict the backend services' outbound traffic to trusted destinations.

  4. D

    Apply a firewall rule on the backend VPC to deny all ingress traffic except from the Load Balancer.

  5. E

    Set up a custom DNS server for the backend services to restrict DNS resolution to specific domains.

Show answer and explanation

Correct answers: A, B, C

Explanation

To meet security and data exfiltration prevention requirements, it is crucial to combine multiple layers of protection. Cloud Armor enforces access control policies for trusted IP ranges, while VPC Service Controls create a secure perimeter that prevents unauthorized access and data exfiltration. Cloud NAT restricts backend services' outbound traffic to trusted destinations. These steps combined ensure both inbound and outbound traffic is tightly controlled. However, firewall rules and custom DNS servers are either redundant or insufficient for the presented scenario.

  • A. Correct.

    This is correct. Cloud Armor allows you to create security policies that can restrict traffic to trusted IP ranges, ensuring only authorized sources can access the Load Balancer.

  • B. Correct.

    This is correct. VPC Service Controls help prevent unauthorized data exfiltration by defining a service perimeter that restricts access to the backend services.

  • C. Correct.

    This is correct. Cloud NAT ensures that backend services can only send outbound traffic through the NAT gateway, and you can configure it to allow connections only to trusted destinations.

  • D. Incorrect.

    This is incorrect. While a firewall rule can restrict ingress traffic to the backend VPC, the Load Balancer already manages ingress traffic filtering, and this does not prevent data exfiltration.

  • E. Incorrect.

    This is incorrect. Setting up a custom DNS server may enhance domain filtering but does not comprehensively address data exfiltration prevention or traffic restriction requirements.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam