Google Professional Cloud Network Engineer Question 495
Select 3Google Cloud PlatformYour organization is using Google Cloud to host a series of web applications. You want to enhance your network security by leveraging Google Threat Intelligence to protect against malicious IPs and domains. Which of the following steps should you take to integrate Google Threat Intelligence into your network security strategy?
- A
Enable Google Cloud Armor to filter traffic based on known malicious IPs and domains.
- B
Use VPC Service Controls to automatically block all traffic from IPs flagged by Google Threat Intelligence.
- C
Regularly review the Google Cloud Threat Intelligence Dashboard to identify threats and refine firewall rules.
- D
Integrate Google Threat Intelligence signals into custom rule configurations for Cloud Armor.
- E
Activate default threat detection rules in Google Cloud’s Security Command Center to monitor potential vulnerabilities.
Show answer and explanation
Correct answers: A, C, D
Explanation
To apply Google Threat Intelligence effectively, you can leverage tools like Google Cloud Armor to block malicious traffic using predefined or custom rules based on threat intelligence signals. Regularly reviewing threat intelligence dashboards further helps in identifying risks and fine-tuning your security posture. While VPC Service Controls and Security Command Center enhance overall security, they do not directly integrate Google Threat Intelligence for traffic filtering.
- A. Correct.
Correct: Google Cloud Armor can use threat intelligence signals to filter out traffic from known malicious sources, providing protection against threats.
- B. Incorrect.
Incorrect: VPC Service Controls are used to restrict data exfiltration and access between services, but they do not automatically block traffic based on Google Threat Intelligence.
- C. Correct.
Correct: Regularly reviewing the Google Cloud Threat Intelligence Dashboard can help you stay updated on potential risks and adjust your security configurations effectively.
- D. Correct.
Correct: Custom rules in Cloud Armor can be configured to use Google Threat Intelligence signals, allowing for specific filtering of malicious traffic.
- E. Incorrect.
Incorrect: Security Command Center’s threat detection rules help monitor and detect vulnerabilities, but they do not directly integrate Google Threat Intelligence into network traffic filtering.