Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 496 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 496

Select 3Google Cloud Platform

Your organization uses Google Cloud's Virtual Private Cloud (VPC) to host its applications. Recently, your security team detected an increase in suspicious traffic patterns and potential threats targeting your public-facing workloads. You want to leverage Google Threat Intelligence to enhance your network security posture and block malicious activities. Which features or services can you use to achieve this?

  1. A

    Enable Google Cloud Armor's Adaptive Protection to detect and mitigate Layer 7 DDoS attacks based on Google Threat Intelligence.

  2. B

    Configure VPC Service Controls to restrict access to Google Cloud services using Google Threat Intelligence data.

  3. C

    Use the Threat Intelligence for Network Firewall feature to block traffic from malicious IPs identified by Google.

  4. D

    Enable Security Command Center Premium and configure it to use Google Threat Intelligence for real-time threat detection.

  5. E

    Deploy Cloud IDS to monitor network traffic for known malicious behaviors and threats using Google Threat Intelligence.

Show answer and explanation

Correct answers: A, C, E

Explanation

Google Threat Intelligence integrates with specific Google Cloud services to enhance network security. Google Cloud Armor's Adaptive Protection, Threat Intelligence for Network Firewall, and Cloud IDS are examples of services that actively use threat intelligence to detect, block, or alert on malicious activities, making them the right answers for this scenario. VPC Service Controls and Security Command Center Premium, while useful for security, do not directly apply Google Threat Intelligence for this purpose.

  • A. Correct.

    Google Cloud Armor's Adaptive Protection uses Google Threat Intelligence to detect and mitigate Layer 7 attacks. This is a valid option for leveraging threat intelligence.

  • B. Incorrect.

    VPC Service Controls enhance data exfiltration prevention but do not specifically use Google Threat Intelligence for blocking or monitoring traffic.

  • C. Correct.

    Threat Intelligence for Network Firewall allows Google Cloud's firewall rules to leverage Google Threat Intelligence to block traffic from known malicious IPs. This is a valid use case.

  • D. Incorrect.

    While Security Command Center Premium offers threat detection capabilities, it does not directly block or mitigate threats using Google Threat Intelligence.

  • E. Correct.

    Cloud IDS uses Google Threat Intelligence to identify and alert on malicious behaviors and threats in network traffic. This is a valid option for leveraging threat intelligence.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam