Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 350 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 350

Select 3Google Cloud Platform

Your organization is deploying a new application on Google Cloud. The deployment requires fine-grained network access control to allow communication between specific VM instances and block unauthorized traffic. You need to use network tags, service accounts, and secure tags effectively to achieve this. Which steps should you take to implement this requirement?

  1. A

    Assign network tags to VM instances and reference these tags in firewall rules to allow or deny traffic.

  2. B

    Use secure tags to dynamically group VM instances and reference them in firewall rules.

  3. C

    Create a service account for each VM instance and use it directly in firewall rules to control access.

  4. D

    Combine network tags with secure tags to create more complex firewall rules.

  5. E

    Rely only on service accounts for access control without using network tags or secure tags.

Show answer and explanation

Correct answers: A, B, D

Explanation

To implement fine-grained network access control, you should use a combination of network tags and secure tags in your firewall rules. Network tags allow you to statically assign access control policies to specific VM instances, while secure tags enable dynamic grouping of resources based on metadata. Combining these methods can provide highly flexible and secure access control. Service accounts, while crucial for identity and permissions, are not directly used in firewall rules for network traffic control.

  • A. Correct.

    Correct: Network tags can be assigned to VM instances and used in firewall rules to control access. This is a standard approach in Google Cloud to manage traffic effectively.

  • B. Correct.

    Correct: Secure tags allow dynamic grouping of resources, and they can be referenced in firewall rules for flexible access control. This is a recommended practice in scenarios requiring dynamic configurations.

  • C. Incorrect.

    Incorrect: While service accounts provide identity to VM instances, they are not directly used in firewall rules for network access control. Firewall rules are based on tags and IP ranges.

  • D. Correct.

    Correct: Combining network tags with secure tags can provide more advanced firewall configurations, such as allowing traffic between dynamically grouped resources while maintaining static rules for other instances.

  • E. Incorrect.

    Incorrect: Relying solely on service accounts does not provide the necessary granularity for network access control. Network tags and secure tags are required for defining and enforcing firewall rules.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam