Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 379 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 379

Select 2Google Cloud Platform

Your organization is hosting a web application on Google Cloud using Compute Engine instances behind a Google Cloud HTTP(S) Load Balancer. To enhance security, you want to configure the Intrusion Prevention Service (IPS) to block known malicious traffic targeting your backend instances. Which of the following steps are required to properly configure IPS within your Google Cloud environment?

  1. A

    Enable Google Cloud Armor and configure a security policy with IPS rules.

  2. B

    Create a VPC network firewall rule to apply IPS signatures.

  3. C

    Deploy a third-party IPS appliance from the Google Cloud Marketplace and connect it to your network.

  4. D

    Ensure your backend instances are in a subnet with Private Google Access enabled.

  5. E

    Enable Traffic Director to route traffic through the IPS appliance.

Show answer and explanation

Correct answers: A, C

Explanation

To configure IPS in Google Cloud, you can leverage Google Cloud Armor, which integrates IPS capabilities through security policies to block malicious traffic. Alternatively, you can deploy a third-party IPS appliance from the Google Cloud Marketplace. VPC firewall rules, Private Google Access, and Traffic Director are unrelated to IPS functionality.

  • A. Correct.

    Correct. Google Cloud Armor integrates with IPS, allowing you to define security policies that include IPS rules to block malicious traffic targeting your application.

  • B. Incorrect.

    Incorrect. VPC firewall rules do not support IPS configurations directly. IPS functionality must be implemented through Google Cloud Armor or third-party appliances.

  • C. Correct.

    Correct. Using a third-party IPS appliance from the Google Cloud Marketplace is a valid approach to implement intrusion prevention in Google Cloud.

  • D. Incorrect.

    Incorrect. Private Google Access is used for allowing instances to access Google APIs and services privately and is not related to IPS configuration.

  • E. Incorrect.

    Incorrect. Traffic Director is used for service mesh and traffic management. It is not required for configuring IPS.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam