Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 451 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 451

Select 3Google Cloud Platform

Your organization hosts a web application on Google Cloud, and the security team has identified a surge in malicious traffic originating from specific IP ranges. You are tasked with configuring a Google Cloud Armor policy to block this traffic while ensuring legitimate users can still access the application. What steps should you take to achieve this?

  1. A

    Create a Google Cloud Armor security policy and add a rule to block traffic from the identified IP ranges.

  2. B

    Set the action of the rule to 'deny(403)' for the identified IP ranges.

  3. C

    Attach the Google Cloud Armor security policy to the backend service used by the web application.

  4. D

    Enable adaptive protection in Google Cloud Armor to block all incoming traffic temporarily.

  5. E

    Add a rule in the security policy to allow all requests from other IP ranges.

Show answer and explanation

Correct answers: A, B, C

Explanation

To block malicious traffic from specific IP ranges using Google Cloud Armor, you need to create a security policy and add a rule that matches the identified IP ranges. The rule's action should be set to 'deny(403)' to block the traffic. Finally, the security policy must be attached to the backend service used by the web application, ensuring the policy applies to all incoming traffic. Adaptive protection and additional allow rules are not required for this specific use case.

  • A. Correct.

    Correct. Creating a security policy and adding a rule to block traffic from specific IP ranges is the first step to mitigate malicious traffic.

  • B. Correct.

    Correct. Setting the action to 'deny(403)' ensures that traffic from the identified IP ranges is blocked effectively.

  • C. Correct.

    Correct. Attaching the security policy to the backend service ensures that the policy is applied to incoming traffic for the web application.

  • D. Incorrect.

    Incorrect. While adaptive protection is useful for detecting and mitigating sophisticated attacks, it is not specific to blocking traffic from certain IP ranges, and temporarily blocking all traffic may disrupt legitimate access.

  • E. Incorrect.

    Incorrect. Adding a rule to allow all requests from other IP ranges is not necessary in this scenario because by default, rules in Google Cloud Armor are evaluated in sequence, and traffic not explicitly blocked will be allowed if no deny rule matches.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam