Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 739 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 739

Select 4Google Cloud Platform

Your organization uses Cloud NGFW (Next-Generation Firewall) on Google Cloud to secure traffic between multiple VPC networks. A new policy rule was added to block outbound traffic to a specific IP range, but users are reporting that traffic to this IP range is still allowed. Which of the following actions should you take to troubleshoot and resolve the issue?

  1. A

    Verify the priority of the new rule to ensure it is evaluated before more permissive rules.

  2. B

    Check the Cloud NGFW logs to confirm whether matching traffic is being evaluated against the correct rule.

  3. C

    Ensure the new rule was deployed and the policy is attached to the correct VPC networks.

  4. D

    Modify the rule to use the 'allow' action instead of 'deny' to test connectivity.

  5. E

    Confirm that the destination IP range is not overlapping with an existing more permissive rule.

Show answer and explanation

Correct answers: A, B, C, E

Explanation

To effectively troubleshoot Cloud NGFW rules or policies, it is important to verify rule priority, evaluate logs to identify matching traffic, ensure the policy is correctly deployed, and check for overlaps with existing rules. These steps help isolate and resolve issues with firewall rule behavior.

  • A. Correct.

    Firewall rules in Cloud NGFW are evaluated based on priority. If a rule with a lower priority (higher number) conflicts with a more permissive rule of higher priority, the traffic may not be blocked as intended.

  • B. Correct.

    Logs can help identify whether the traffic is matching the intended rule or being evaluated against another rule. This step is critical to troubleshoot the issue.

  • C. Correct.

    If the policy is not properly deployed or attached to the correct VPC networks, the rule will not take effect. Verifying this ensures the rule is active in the intended scope.

  • D. Incorrect.

    Modifying the rule to 'allow' would contradict the goal of blocking traffic. This action does not help troubleshoot the issue and could introduce security risks.

  • E. Correct.

    Overlapping IP ranges with a more permissive rule could cause the traffic to bypass the new deny rule. Ensuring no overlap is critical to the rule's effectiveness.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam