Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 372 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 372

Select 2Google Cloud Platform

Your organization has a Google Cloud environment with multiple projects under a single folder. You need to configure a hierarchical firewall policy that ensures the following:

  1. Block all inbound SSH traffic across all projects.
  2. Allow only internal traffic within a specific project for a certain subnet.

How should you configure the hierarchical firewall policies to achieve this?

  1. A

    Create a rule in the organization's hierarchical firewall policy to deny all SSH traffic, and set its priority higher (lower number) than other rules.

  2. B

    Create a rule in the folder's hierarchical firewall policy to deny all SSH traffic, and set its priority higher (lower number) than other rules.

  3. C

    Create a rule in the folder's hierarchical firewall policy to allow internal traffic for the specific subnet and set its priority lower (higher number) than the SSH deny rule.

  4. D

    Create a rule in the project's VPC firewall to allow internal traffic for the specific subnet and set its priority higher (lower number) than the SSH deny rule.

  5. E

    Create a rule in the organization's hierarchical firewall policy to allow internal traffic for the specific subnet and set its priority higher (lower number) than the SSH deny rule.

Show answer and explanation

Correct answers: B, C

Explanation

Hierarchical firewall policies allow you to enforce security rules across multiple projects in a structured manner. To block SSH traffic across all projects, a deny rule should be configured at the folder level with a high priority. To allow internal traffic for a specific subnet, an allow rule can be added at the folder level with a lower priority, ensuring the exception is applied without overriding the global SSH deny rule. This approach ensures proper enforcement of both rules across the projects in the folder.

  • A. Incorrect.

    This option is incorrect because an organization-level rule would apply globally across all projects, which may block SSH traffic even for intended exceptions.

  • B. Correct.

    This option is correct because applying the SSH deny rule at the folder level ensures all projects under the folder inherit this rule, while still allowing for project-specific exceptions.

  • C. Correct.

    This option is correct because allowing internal traffic for a specific subnet at the folder level ensures that this exception is applied after the SSH deny rule due to its lower priority.

  • D. Incorrect.

    This option is incorrect because project-level VPC firewall rules cannot override a hierarchical firewall policy configured at the folder or organization level.

  • E. Incorrect.

    This option is incorrect because allowing internal traffic at the organization level could unintentionally apply the exception to all projects, which does not meet the requirement.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam