Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 467 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 467

Single answerGoogle Cloud Platform

Your company hosts a web application using a Google Cloud HTTP(S) Load Balancer with multiple backend services. For security purposes, you need to restrict access to one of the backend services based on IP address ranges while allowing unrestricted access to other backend services. What is the correct approach to achieve this?

  1. A

    Attach a security policy to the HTTP(S) Load Balancer frontend.

  2. B

    Attach a security policy to the specific backend service.

  3. C

    Configure a firewall rule to restrict traffic to the backend service.

  4. D

    Use Cloud Armor to create a security policy and apply it to the specific backend service.

Show answer and explanation

Correct answer: D

Explanation

To restrict access to a specific backend service in an HTTP(S) Load Balancer, you must use Cloud Armor. Cloud Armor enables you to create security policies that can filter traffic based on attributes like IP address ranges and apply them to individual backend services. This approach is precise and integrates seamlessly with Google Cloud's load balancing architecture.

  • A. Incorrect.

    Incorrect: Security policies cannot be attached to the HTTP(S) Load Balancer frontend. Security policies must be applied to backend services or targets within the load balancer.

  • B. Incorrect.

    Incorrect: Google Cloud does not support directly attaching security policies to backend services. Instead, you must use Cloud Armor to manage and apply such policies.

  • C. Incorrect.

    Incorrect: Firewall rules operate at the network level, not at the load balancer level, and cannot be used to restrict traffic for specific backend services of a load balancer.

  • D. Correct.

    Correct: Cloud Armor allows you to create security policies that can restrict access based on IP ranges. These policies can be applied to specific backend services within an HTTP(S) Load Balancer, providing the desired level of control.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam