Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 622 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 622

Select 4Google Cloud Platform

You are a network engineer managing a Google Cloud environment for a retail company. The company needs to inspect HTTP and HTTPS traffic for advanced threat detection and enforce application-layer policies. You decide to enable Layer 7 packet inspection using Google Cloud's Next Generation Firewall (Cloud NGFW). What steps should you take to achieve this?

  1. A

    Deploy Cloud NGFW and configure an inspection policy that includes Layer 7 features like application filtering.

  2. B

    Enable the SSL/TLS decryption feature in Cloud NGFW for HTTPS traffic inspection.

  3. C

    Configure IAM roles to grant the 'roles/compute.networkAdmin' role to allow Cloud NGFW to access resources.

  4. D

    Ensure traffic is routed to the Cloud NGFW by configuring a custom static route in your VPC.

  5. E

    Configure a Cloud Armor policy for Layer 7 inspection and attach it to your Cloud NGFW instance.

  6. F

    Ensure a license is purchased and activated for Cloud NGFW to enable advanced Layer 7 features.

Show answer and explanation

Correct answers: A, B, D, F

Explanation

To enable Layer 7 packet inspection with Cloud NGFW in Google Cloud, you need to deploy the firewall, configure it with appropriate Layer 7 rules, and enable SSL/TLS decryption for HTTPS traffic. Additionally, routing must be configured to ensure traffic flows through the firewall. Licensing is required to activate advanced features like application filtering and threat detection. IAM roles and Cloud Armor policies are not directly related to enabling Layer 7 packet inspection in Cloud NGFW.

  • A. Correct.

    Correct. Cloud NGFW needs to be deployed and configured with rules that leverage Layer 7 features such as application filtering and threat detection.

  • B. Correct.

    Correct. To inspect HTTPS traffic, SSL/TLS decryption must be enabled so that encrypted traffic can be analyzed.

  • C. Incorrect.

    Incorrect. IAM roles like 'roles/compute.networkAdmin' are necessary for managing network resources but are not required specifically for enabling Layer 7 packet inspection in Cloud NGFW.

  • D. Correct.

    Correct. Traffic must be routed to the Cloud NGFW instance using custom static routes or other routing mechanisms to ensure it passes through the firewall.

  • E. Incorrect.

    Incorrect. Cloud Armor policies are separate from Cloud NGFW and are not used for enabling Layer 7 packet inspection. Cloud Armor focuses on DDoS protection and web application security.

  • F. Correct.

    Correct. Cloud NGFW requires proper licensing to enable and use its advanced features, including Layer 7 packet inspection.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam