Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 346 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 346

Select 2Google Cloud Platform

Your company is running a multi-region application hosted in Google Cloud. The application requires that all instances in the network can only be accessed over SSH from a specific set of external IP addresses. Additionally, a global policy should ensure that no traffic is allowed to reach instances unless explicitly permitted. How can you achieve this requirement?

  1. A

    Create a global network firewall policy with a deny-all ingress rule and attach it to all VPC networks.

  2. B

    Create a VPC firewall rule in each region to allow ingress SSH traffic only from the specific external IP addresses.

  3. C

    Use hierarchical firewall policies to define a deny-all ingress rule at the organization level.

  4. D

    Create a regional network firewall policy with a default deny-all ingress rule and an allow rule for SSH traffic from the specific external IP addresses.

  5. E

    Use a service perimeter to restrict access to SSH traffic globally.

Show answer and explanation

Correct answers: A, B

Explanation

To secure the network, a deny-all ingress rule is required as a baseline, which can be implemented using a global network firewall policy. In addition, specific allow rules for SSH traffic from the given external IP addresses must be created using VPC firewall rules in each region to meet the application's accessibility requirements. Hierarchical and regional policies, while useful in other cases, are not suitable for this scenario, and service perimeters do not apply to SSH traffic.

  • A. Correct.

    This is correct. A global network firewall policy with a deny-all ingress rule provides a baseline security policy ensuring no traffic is allowed by default unless explicitly permitted.

  • B. Correct.

    This is correct. VPC firewall rules in each region allow you to permit ingress SSH traffic only from the specific external IP addresses, meeting the application requirement.

  • C. Incorrect.

    This is incorrect. While hierarchical firewall policies can be used at the organization level, they are not required in this scenario since global network firewall policies effectively manage the deny-all rule.

  • D. Incorrect.

    This is incorrect. Regional network firewall policies are not used in this scenario because the deny-all rule needs to apply globally, not regionally.

  • E. Incorrect.

    This is incorrect. Service perimeters are used for controlling access to Google-managed services (like APIs) and are not applicable to configuring SSH traffic rules.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam