Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 335 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 335

Select 4Google Cloud Platform

Your organization is deploying a Cloud Next Generation Firewall (NGFW) in Google Cloud to protect its workloads. You are tasked with configuring NGFW rules to allow traffic from a specific set of IP addresses and block all others. Which of the following considerations should you account for while configuring the NGFW rules?

  1. A

    Ensure that the rule priority is set correctly, as lower numbers indicate higher priority.

  2. B

    Use service accounts as the source for the allow rule instead of IP addresses, since IP-based rules are not supported.

  3. C

    Configure logging for the NGFW rules to monitor allowed and denied traffic.

  4. D

    Set the rule action to 'allow' for the specific IP addresses, and ensure a default 'deny' rule is in place for all other traffic.

  5. E

    Apply the NGFW rules to the firewall policies associated with the target VPC network.

Show answer and explanation

Correct answers: A, C, D, E

Explanation

When configuring Cloud Next Generation Firewall (NGFW) rules in Google Cloud, proper rule priority ensures the rules are processed in the intended order. Logging is essential for monitoring traffic and maintaining security audits. The rules must explicitly allow traffic for the specified IP addresses and block all others with a default 'deny' rule. Finally, the rules must be applied to the VPC network's firewall policies to enforce them. Service accounts are not required for IP-based filtering, making this option incorrect.

  • A. Correct.

    Correct: NGFW rules are processed in order of priority, where lower numbers have higher priority. Misconfiguring priorities can lead to unintended traffic behavior.

  • B. Incorrect.

    Incorrect: NGFW supports IP-based filtering, and service accounts are not required as sources for allow rules in this scenario.

  • C. Correct.

    Correct: Logging is a critical consideration for tracking and auditing what traffic was allowed or denied by the rules.

  • D. Correct.

    Correct: NGFW rules must explicitly allow the required IP addresses with an 'allow' action, and a default 'deny' rule ensures that all other traffic is blocked.

  • E. Correct.

    Correct: For NGFW rules to take effect, they must be applied to the firewall policies associated with the appropriate VPC network.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam