Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 96 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 96

Single answerGoogle Cloud Platform

Your company operates a multi-project environment in Google Cloud. You are tasked with implementing a firewall strategy to enforce security policies across multiple projects while maintaining centralized control. The solution should ensure consistent rules for all VPC networks in the organization, regardless of the project. Which approach should you take?

  1. A

    Use VPC firewall rules in each project to define the security policies.

  2. B

    Implement Cloud Next Generation Firewall policies in each VPC network.

  3. C

    Set up hierarchical firewall rules at the organization or folder level.

  4. D

    Use custom IAM roles to manage firewall rules consistently across projects.

Show answer and explanation

Correct answer: C

Explanation

Hierarchical firewall rules are designed to enforce security policies at the organization or folder level. This allows you to create rules that apply consistently across all VPC networks in all projects under the organization or folder, ensuring centralized control and avoiding the need to replicate rules manually in each project. This makes hierarchical firewall rules the best approach for the given scenario.

  • A. Incorrect.

    VPC firewall rules are project-specific, meaning you would need to replicate the rules across all projects, which is not centralized or efficient for enforcing organization-wide policies.

  • B. Incorrect.

    While Cloud Next Generation Firewall can be used for advanced security, it is still scoped to individual VPC networks and does not provide centralized control for multiple projects.

  • C. Correct.

    Hierarchical firewall rules are applied at the organization or folder level, making them an ideal solution for enforcing consistent and centralized security policies across multiple projects.

  • D. Incorrect.

    IAM roles control access to resources but do not define or enforce firewall rules. This option does not address the requirement for implementing a firewall strategy.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam