Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 198 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 198

Select 3Google Cloud Platform

Your organization is deploying a new web application in Google Cloud, and you are tasked with setting up advanced security measures for HTTP traffic. The organization uses Cloud NGFW to enforce security policies. You need to configure application layer (Layer 7) inspection on Cloud NGFW to detect and block malicious HTTP payloads. What steps should you take?

  1. A

    Enable Deep Packet Inspection (DPI) in Cloud NGFW and configure signatures for HTTP traffic.

  2. B

    Create a URL Filtering profile in Cloud NGFW to inspect and block specific URLs.

  3. C

    Enable SSL decryption in Cloud NGFW for encrypted HTTP traffic and configure inspection rules.

  4. D

    Configure custom Layer 7 application filters to define specific payload inspection rules.

  5. E

    Set up an IAM policy to restrict access to the Cloud NGFW configuration interface.

Show answer and explanation

Correct answers: A, C, D

Explanation

To set up application layer inspection (Layer 7) on Cloud NGFW, you need to configure Deep Packet Inspection (DPI) to analyze HTTP payloads, enable SSL decryption to inspect encrypted traffic, and use custom application filters to define specific rules. These settings ensure comprehensive traffic analysis at the application layer. URL Filtering and IAM policies, while important for overall security, are not directly related to Layer 7 payload inspection.

  • A. Correct.

    This is correct. Deep Packet Inspection (DPI) is a key feature of Cloud NGFW for analyzing Layer 7 traffic and detecting malicious payloads.

  • B. Incorrect.

    This is incorrect. While URL Filtering is useful for controlling access to specific URLs, it does not perform payload inspection at the application layer.

  • C. Correct.

    This is correct. Enabling SSL decryption allows Cloud NGFW to analyze encrypted HTTP (HTTPS) traffic, which is essential for thorough Layer 7 inspection.

  • D. Correct.

    This is correct. Custom Layer 7 application filters allow you to define rules for inspecting specific application-level payloads.

  • E. Incorrect.

    This is incorrect. While IAM policies are critical for securing access to Cloud NGFW management, they are not related to application layer inspection.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam