Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 373 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 373

Select 2Google Cloud Platform

Your organization has a Google Cloud project named 'prod-environment' under a folder 'production' in the organization hierarchy. You are tasked with configuring a hierarchical firewall policy to allow SSH traffic (port 22) only to a specific set of VM instances in the 'prod-environment' project while blocking SSH traffic elsewhere. Where should you apply the rules to achieve this requirement?

  1. A

    Create a rule at the organization level to block SSH traffic and then create a rule at the folder level to allow SSH traffic to the specific VM instances.

  2. B

    Create a rule at the organization level to block SSH traffic and then create a rule at the project level to allow SSH traffic to the specific VM instances.

  3. C

    Create a rule at the folder level to block SSH traffic and then create a rule at the project level to allow SSH traffic to the specific VM instances.

  4. D

    Create a rule at the folder level to allow SSH traffic to the specific VM instances and then create a rule at the organization level to block SSH traffic.

  5. E

    Create a rule at the project level to allow SSH traffic to the specific VM instances and then rely on the default Google Cloud firewall rules to block SSH traffic elsewhere.

Show answer and explanation

Correct answers: B, C

Explanation

Hierarchical firewall policies allow you to enforce security rules at different levels of the resource hierarchy: organization, folder, and project. Rules with the lowest priority (highest numerical value) are applied first, and more specific rules closer to the resource take precedence. To achieve the requirement of blocking SSH traffic broadly while allowing it to specific VM instances, you can block SSH traffic at a higher level (organization or folder) and then allow it at the project level for specific resources. This ensures security and adherence to the principle of least privilege.

  • A. Incorrect.

    This approach would not work because rules at the folder level cannot override rules set at the organization level. Hierarchical firewall policies follow the principle of least privilege and more specific rules must be applied closer to the resource.

  • B. Correct.

    This is a valid approach. Rules at the organization level can provide a broad restriction (e.g., blocking SSH), while project-level rules can allow specific traffic (e.g., SSH to certain VMs). The project-level rules take precedence over the organization-level rules for resources in the project.

  • C. Correct.

    This is a valid approach. Rules at the folder level can block SSH traffic broadly across all projects under the folder, while project-level rules can allow SSH traffic to specific VM instances within the 'prod-environment' project. The project-level rules override the folder-level rules for resources in the project.

  • D. Incorrect.

    This approach would not work because broader rules (e.g., organization-level rules) override more specific rules (e.g., folder-level rules) when there is a conflict. Also, allowing traffic at a higher level defeats the purpose of blocking it broadly.

  • E. Incorrect.

    This approach would not work because relying on default Google Cloud firewall rules is not sufficient to block SSH traffic elsewhere. Default rules allow SSH traffic by default, so explicit rules are required to block it.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam