Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 572 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 572

Select 3Google Cloud Platform

You are working for a company that wants to secure internet egress traffic for its applications hosted on Google Cloud. The company's requirements include restricting outbound traffic to certain domains, ensuring compliance with organizational policies, and logging all egress traffic for audit purposes. Which combination of Google Cloud solutions should you use to meet these requirements?

  1. A

    Configure a Cloud NAT instance to manage outbound internet traffic from private VM instances.

  2. B

    Use VPC Service Controls to restrict access to specific domains for egress traffic.

  3. C

    Implement a Private Google Access configuration to route traffic to Google APIs and services securely.

  4. D

    Deploy a Cloud Armor security policy with custom rules for blocking or allowing traffic based on domain names.

  5. E

    Set up a Google Cloud Firewall rule with egress filtering for specific IP ranges.

  6. F

    Use a third-party proxy or custom solution to enforce domain-based restrictions and log egress traffic.

Show answer and explanation

Correct answers: A, E, F

Explanation

To secure and control internet egress traffic effectively while meeting the requirements for domain-based restrictions and logging, you can combine solutions. Cloud NAT allows private VM instances to access the internet for egress traffic. Google Cloud Firewall rules help enforce egress filtering based on IP ranges, while a third-party proxy or custom solution can enforce domain-based restrictions and provide detailed logging for audit purposes. These solutions together address the company's needs comprehensively.

  • A. Correct.

    Cloud NAT enables private VM instances to access the internet for egress traffic, but it does not directly enforce domain-based restrictions or logging.

  • B. Incorrect.

    VPC Service Controls are designed for securing data exchange between Google Cloud services, not for restricting egress traffic to specific domains.

  • C. Incorrect.

    Private Google Access allows private VM instances to connect to Google APIs and services, but it does not provide domain-based restrictions or logging for general egress traffic.

  • D. Incorrect.

    Cloud Armor is primarily used for securing inbound traffic to applications and does not support domain-based outbound traffic filtering.

  • E. Correct.

    Google Cloud Firewall rules can be used to define egress filtering policies, such as allowing or denying traffic to specific IP ranges, but they do not natively enforce domain-based restrictions.

  • F. Correct.

    A third-party proxy or custom solution can provide advanced functionality for domain-based restrictions and detailed logging for compliance purposes, making it a viable option for this scenario.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam