Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 499 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 499

Single answerGoogle Cloud Platform

Your organization is using Google Cloud and wants to enhance its network security by leveraging Google Threat Intelligence data. You need to configure a solution that can automatically detect and block known malicious IP addresses in real-time. Which solution should you implement to meet this requirement?

  1. A

    Use Google Cloud Armor with pre-configured WAF rules that include threat intelligence signals.

  2. B

    Enable VPC Service Controls to restrict access to sensitive data based on threat intelligence data.

  3. C

    Configure Google Cloud Firewall rules with threat intelligence feeds to block malicious IP addresses.

  4. D

    Implement Traffic Director to automatically route traffic away from IPs flagged by Google Threat Intelligence.

Show answer and explanation

Correct answer: A

Explanation

Google Cloud Armor is the appropriate solution for leveraging Google Threat Intelligence to enhance network security. It offers pre-configured WAF rules that utilize threat intelligence signals to detect and block malicious IPs in real-time. Other options, such as VPC Service Controls, Google Cloud Firewall, and Traffic Director, do not provide direct integration with threat intelligence for dynamically managing threats.

  • A. Correct.

    Correct. Google Cloud Armor integrates with Google Threat Intelligence to provide pre-configured WAF rules that can detect and block traffic from malicious IPs in real-time.

  • B. Incorrect.

    Incorrect. VPC Service Controls are used to protect sensitive resources from unauthorized access, but they do not incorporate threat intelligence data for blocking malicious IPs.

  • C. Incorrect.

    Incorrect. Google Cloud Firewall does not directly integrate with threat intelligence feeds for automatic malicious IP blocking.

  • D. Incorrect.

    Incorrect. Traffic Director is used for service mesh and traffic routing, but it does not use Google Threat Intelligence to block malicious IPs.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam