Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 468 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 468

Single answerGoogle Cloud Platform

You are configuring a Google Cloud HTTPS Load Balancer to serve traffic for a web application. The application has sensitive data, and you need to restrict access to specific backend services based on security policies. How can you achieve this?

  1. A

    Attach a Google Cloud Armor security policy to the backend services.

  2. B

    Use Identity and Access Management (IAM) roles to restrict access to the backend services.

  3. C

    Configure firewall rules to allow traffic only from the load balancer to the backend services.

  4. D

    Set up a Cloud Functions trigger to validate access requests before routing them to backend services.

Show answer and explanation

Correct answer: A

Explanation

To enforce access restrictions and protect backend services behind a load balancer, you can attach Google Cloud Armor security policies. These policies allow you to define rules to control traffic and protect resources from threats such as SQL injection or cross-site scripting (XSS). Other mechanisms like IAM, firewall rules, or Cloud Functions are either administrative tools or not designed for this specific use case.

  • A. Correct.

    Correct. Google Cloud Armor security policies are specifically designed to provide access control and protection based on security rules for backend services of a load balancer.

  • B. Incorrect.

    Incorrect. IAM roles control access to Google Cloud resources at an administrative level, not for traffic routing or backend service access restrictions.

  • C. Incorrect.

    Incorrect. While firewall rules can restrict traffic based on IP ranges, they do not provide advanced security policies or granular control specific to backend services.

  • D. Incorrect.

    Incorrect. Cloud Functions triggers are used for event-driven executions but are not designed to enforce security policies for load balancer backends.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam