Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 369 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 369

Select 3Google Cloud Platform

You are tasked with enabling firewall rules logging for a specific VPC firewall rule in your Google Cloud project. After enabling logging, you need to ensure that the logs are collected and visible in Cloud Logging for analysis. Which of the following steps must you take to achieve this?

  1. A

    Enable the 'Logs' option for the firewall rule in the Google Cloud Console or via gcloud CLI.

  2. B

    Set up a log sink in Cloud Logging to export the logs to BigQuery for long-term analysis.

  3. C

    Ensure the VPC Flow Logs feature is enabled for the subnet associated with the firewall rule.

  4. D

    Verify that the IAM role 'roles/logging.logWriter' is assigned to the Google-managed service account.

  5. E

    Modify the firewall rule's action to 'Deny' to ensure logging is triggered.

  6. F

    Check the Cloud Logging Logs Explorer to confirm that logs are being generated.

Show answer and explanation

Correct answers: A, D, F

Explanation

To configure firewall rules logging, you must first enable the 'Logs' option for the firewall rule, ensure that the appropriate IAM permissions are in place for the Google-managed service account to write logs, and verify that the logs are being generated and visible in Cloud Logging. While other steps like exporting logs to BigQuery or enabling VPC Flow Logs might be useful in specific scenarios, they are not directly required for enabling or verifying firewall rules logging.

  • A. Correct.

    Correct. Enabling the 'Logs' option for the firewall rule is necessary to start logging traffic that matches the rule.

  • B. Incorrect.

    Incorrect. While exporting logs to BigQuery can be useful for long-term analysis, it is not required for enabling or viewing firewall rule logs in Cloud Logging.

  • C. Incorrect.

    Incorrect. VPC Flow Logs is a separate feature that logs network flows and is not directly related to firewall rules logging.

  • D. Correct.

    Correct. The 'roles/logging.logWriter' IAM role must be assigned to the Google-managed service account so it can write logs to Cloud Logging.

  • E. Incorrect.

    Incorrect. Changing the firewall rule to 'Deny' is not a requirement for enabling logging. Logging works regardless of whether the rule allows or denies traffic.

  • F. Correct.

    Correct. After enabling logging, it's important to verify that logs are being generated and are accessible via the Cloud Logging Logs Explorer.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam