Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 352 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 352

Select 2Google Cloud Platform

You are setting up a firewall rule in Google Cloud to allow ingress traffic on port 443 for a specific set of virtual machines (VMs). The VMs are differentiated by their use of a specific service account and a secure tag. How should you configure the target field in the firewall rule to ensure only these VMs are affected?

  1. A

    Specify the service account associated with the VMs in the firewall rule's target field.

  2. B

    Use network tags to match the VMs and specify them in the firewall rule's target field.

  3. C

    Apply the secure tag to the VMs and specify the tag in the firewall rule's target field.

  4. D

    Specify the VPC network where the VMs are located in the firewall rule's target field.

  5. E

    Use the 'all instances in the network' option to apply the rule to all VMs in the network.

Show answer and explanation

Correct answers: A, C

Explanation

To ensure a firewall rule targets only specific VMs, you can use service accounts and secure tags as criteria. Service accounts allow you to associate firewall rules with the workloads that use those accounts, while secure tags provide an additional layer of granularity for VM identification. Using the VPC network or applying the rule to all instances would result in a broader application of the rule, which is not desired in this scenario.

  • A. Correct.

    Correct. Specifying the service account in the target field ensures that only VMs using that service account are affected by the firewall rule.

  • B. Incorrect.

    Incorrect. Network tags are not mentioned in this specific scenario as a differentiating factor, so this option does not apply.

  • C. Correct.

    Correct. Secure tags can be used to target specific VMs in the firewall rule, ensuring only those VMs are affected.

  • D. Incorrect.

    Incorrect. While the VPC network is important for routing traffic, specifying the VPC network in the firewall rule's target field would apply the rule to all VMs in the network, not just the intended ones.

  • E. Incorrect.

    Incorrect. Using the 'all instances in the network' option would apply the rule to all VMs in the network, which does not meet the requirement to target only specific VMs.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam