Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 469 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 469

Select 2Google Cloud Platform

You are deploying a global application using Google Cloud's HTTP(S) Load Balancer, and you want to restrict access to specific backend services based on IP ranges. Which of the following steps are required to attach a security policy to the load balancer backends?

  1. A

    Create a backend service and associate it with an existing security policy.

  2. B

    Configure a Cloud Armor security policy with the desired IP allowlist or denylist.

  3. C

    Attach the security policy to the frontend of the load balancer.

  4. D

    Apply the security policy to the backend service associated with the load balancer.

  5. E

    Enable firewall rules on the Compute Engine instances serving as backends.

Show answer and explanation

Correct answers: B, D

Explanation

To attach a security policy to load balancer backends, you must configure a Cloud Armor security policy with the desired rules and then apply it to the backend service associated with the load balancer. This ensures that the backend service is protected by the defined access restrictions. Frontend or firewall configuration is not part of this specific process.

  • A. Incorrect.

    Creating a backend service is necessary for the load balancer, but associating a security policy directly at this step is not how Cloud Armor policies are applied.

  • B. Correct.

    This is correct. Configuring a Cloud Armor security policy is required to define the IP allowlist or denylist rules for restricting access.

  • C. Incorrect.

    Security policies in Google Cloud are applied to backend services, not to the frontend of the load balancer.

  • D. Correct.

    This is correct. To enforce the security policy, it must be explicitly applied to the backend service associated with the load balancer.

  • E. Incorrect.

    Firewall rules are a separate consideration and are not required to implement a Cloud Armor security policy. They function at a different layer of the network stack.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam