Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 624 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 624

Select 3Google Cloud Platform

Your organization is deploying Cloud NGFW to secure traffic in Google Cloud. To enable Layer 7 packet inspection for application-level traffic filtering, what steps must you take to correctly configure the Cloud NGFW?

  1. A

    Ensure that a proper URL Filtering profile is assigned to the security policy.

  2. B

    Enable a Threat Prevention profile in the Cloud NGFW configuration.

  3. C

    Configure a network tag and associate it with the Cloud NGFW instance.

  4. D

    Deploy the Cloud NGFW by setting up a firewall policy and attaching it to a VPC network.

  5. E

    Enable HTTPS decryption to inspect encrypted traffic.

Show answer and explanation

Correct answers: A, B, E

Explanation

To enable Layer 7 packet inspection in Cloud NGFW, it's essential to configure features like URL Filtering and Threat Prevention profiles that operate at the application layer. Additionally, enabling HTTPS decryption allows the NGFW to inspect encrypted traffic, ensuring comprehensive monitoring. Network tags and general firewall policy attachments, while necessary for deployment, do not specifically activate Layer 7 inspection capabilities.

  • A. Correct.

    Correct: URL Filtering is crucial for application-level traffic filtering in Layer 7 inspection. It allows you to define rules for web traffic based on application and website URLs.

  • B. Correct.

    Correct: Threat Prevention profiles enable detection and prevention of malicious activities, which is an essential part of Layer 7 packet inspection.

  • C. Incorrect.

    Incorrect: Configuring a network tag is not directly related to enabling Layer 7 packet inspection. Network tags are used to manage traffic routing and firewall rules but not for application-level filtering.

  • D. Incorrect.

    Incorrect: While deploying the Cloud NGFW with a firewall policy is necessary for its operation, it does not specifically enable Layer 7 packet inspection.

  • E. Correct.

    Correct: HTTPS decryption is required to inspect encrypted traffic effectively at Layer 7, ensuring that application-level threats are detected.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam