Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 466 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 466

Single answerGoogle Cloud Platform

You are setting up a Google Cloud HTTP(S) Load Balancer to distribute traffic to your web application. To enhance security, you need to enforce specific security policies on the backend instances. Which step must you take to attach a security policy to the backend instances behind the load balancer?

  1. A

    Attach a Google Cloud Firewall Rule directly to the load balancer's frontend.

  2. B

    Configure a Backend Service and attach a Google Cloud Armor security policy to it.

  3. C

    Enable Identity and Access Management (IAM) permissions on the backend instances.

  4. D

    Attach a custom SSL certificate to the load balancer to handle security policies.

Show answer and explanation

Correct answer: B

Explanation

To attach security policies to load balancer backends in Google Cloud, you must use Google Cloud Armor. This involves configuring a Backend Service and attaching a security policy to it. This setup ensures that traffic is filtered according to the security policy before reaching the backend instances. Other options like firewall rules, IAM permissions, or SSL certificates do not serve this purpose.

  • A. Incorrect.

    Incorrect. Firewall rules apply at the network level and cannot be attached directly to the load balancer frontend. They are used to control ingress and egress traffic on VM instances.

  • B. Correct.

    Correct. Google Cloud Armor security policies can be attached to a Backend Service. This allows you to enforce security policies for traffic processed by the load balancer before it reaches the backend instances.

  • C. Incorrect.

    Incorrect. IAM permissions control access to resources but are not used for attaching security policies to backend instances or load balancers.

  • D. Incorrect.

    Incorrect. SSL certificates are used to secure data in transit but do not enforce security policies on backend instances.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam