Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 374 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 374

Single answerGoogle Cloud Platform

Your company uses Google Cloud and has a folder structure with multiple projects under different folders. You are tasked with implementing firewall rules to allow inbound SSH traffic (port 22) to all instances across the organization while ensuring that project owners cannot override this rule. How should you configure this using hierarchical firewall policies?

  1. A

    Create a hierarchical firewall policy at the organization level with a rule to allow inbound SSH traffic and set the rule's priority lower than any project-level rules.

  2. B

    Apply a hierarchical firewall policy at the folder level with a rule to allow inbound SSH traffic and enable the 'enforce' flag to prevent project-level overrides.

  3. C

    Create a hierarchical firewall policy at the organization level with a rule to allow inbound SSH traffic and enable the 'enforce' flag to prevent project-level overrides.

  4. D

    Define a VPC-specific firewall rule in each project to allow inbound SSH traffic and set the rule's priority lower than any existing rules.

Show answer and explanation

Correct answer: C

Explanation

To allow inbound SSH traffic across all instances in the organization and prevent project owners from overriding the rule, you must use a hierarchical firewall policy at the organization level. The 'enforce' flag ensures that this rule takes precedence over any project-level rules, fulfilling the requirement. Applying the policy at the folder level or using VPC-specific rules would not comprehensively cover all projects or prevent overrides.

  • A. Incorrect.

    This is incorrect because setting a lower priority means that project-level rules with higher priorities can override this rule, which does not meet the requirement to prevent overrides.

  • B. Incorrect.

    This is incorrect because applying the policy at the folder level does not ensure that all projects across the organization are covered, and it may leave some projects unprotected.

  • C. Correct.

    This is correct because creating a hierarchical firewall policy at the organization level with the 'enforce' flag ensures that the rule applies to all projects and cannot be overridden by project-level rules.

  • D. Incorrect.

    This is incorrect because VPC-specific firewall rules are project-specific and would require duplication across all projects. Additionally, project owners could still override these rules.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam