Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 378 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 378

Select 2Google Cloud Platform

You are tasked with securing your organization's workloads on Google Cloud by enabling Intrusion Prevention Service (IPS) within the Network Security infrastructure. Your organization has deployed multiple VPCs with subnets across different regions. You need to configure IPS to monitor and protect traffic within a specific VPC without affecting other VPCs. What steps should you take to correctly configure IPS for this requirement?

  1. A

    Enable Threat Intelligence for the entire Google Cloud project.

  2. B

    Create and configure a Network Security policy for the specific VPC you want to protect.

  3. C

    Enable Intrusion Prevention Service (IPS) in the Network Security policy and attach it to the target VPC.

  4. D

    Configure firewall rules to explicitly allow only trusted traffic into the VPC.

  5. E

    Deploy a Cloud IDS instance for each subnet in the VPC.

Show answer and explanation

Correct answers: B, C

Explanation

To configure Intrusion Prevention Service (IPS) for a specific VPC in Google Cloud, you must create and configure a Network Security policy that includes IPS. Then, you attach this policy to the target VPC for monitoring and protection. Enabling Threat Intelligence or managing firewall rules alone does not meet the requirement of VPC-specific IPS configuration, and deploying Cloud IDS instances is not necessary since IPS operates through Network Security policies rather than standalone instances.

  • A. Incorrect.

    While Threat Intelligence is a useful feature, enabling it for the entire project does not meet the requirement to isolate IPS protection to a specific VPC. This option is incorrect.

  • B. Correct.

    Creating and configuring a Network Security policy for the specific VPC is the correct approach to apply IPS protection to only that VPC. This option is correct.

  • C. Correct.

    Enabling the Intrusion Prevention Service (IPS) within the Network Security policy and attaching it to the target VPC ensures traffic within that VPC is monitored and protected. This option is correct.

  • D. Incorrect.

    Firewall rules are important for managing traffic but are not directly related to configuring IPS. This option is incorrect.

  • E. Incorrect.

    Cloud IDS instances are not required for configuring IPS as IPS operates at the VPC level using Network Security policies. This option is incorrect.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam