Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 336 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 336

Select 3Google Cloud Platform

Your organization has deployed Cloud Next Generation Firewall (NGFW) in Google Cloud. You are tasked with configuring a firewall rule to allow traffic from a specific set of IP ranges to a web application running on Compute Engine instances. However, you need to ensure that this rule does not unintentionally allow traffic from other IP ranges or to other services. Which configuration steps should you take to achieve this goal?

  1. A

    Specify the source IP ranges explicitly in the firewall rule.

  2. B

    Use tags or service accounts to target the specific Compute Engine instances.

  3. C

    Set the priority of the rule to the lowest possible value to avoid conflicting with other rules.

  4. D

    Specify the destination port for HTTP or HTTPS traffic in the firewall rule.

  5. E

    Leave the default 'allow all traffic' action to ensure connectivity.

Show answer and explanation

Correct answers: A, B, D

Explanation

To configure Cloud Next Generation Firewall (NGFW) rules effectively, you must carefully define the source IP ranges, target only the specific resources (using tags or service accounts), and limit the allowed traffic to necessary ports only. This ensures that the firewall rule is both secure and precise, aligning with best practices. Avoid overly permissive configurations such as 'allow all traffic' or misconfigured priorities that could compromise security.

  • A. Correct.

    Correct: Specifying the source IP ranges explicitly ensures that only the intended IP ranges can send traffic to the web application, reducing the risk of unauthorized access.

  • B. Correct.

    Correct: Using tags or service accounts allows you to target the firewall rule to specific Compute Engine instances running the web application, preventing it from affecting other instances.

  • C. Incorrect.

    Incorrect: Setting the priority to the lowest value is not appropriate in this case. A lower priority number (higher precedence) should be used to ensure this rule is applied before broader or less specific rules.

  • D. Correct.

    Correct: Specifying the destination port ensures that only HTTP or HTTPS traffic is allowed, which is critical for securing the web application.

  • E. Incorrect.

    Incorrect: Leaving 'allow all traffic' as the action would contradict the goal of restricting access to specific IP ranges and services, exposing the application to unnecessary risk.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam