Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 243 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 243

Select 2Google Cloud Platform

Your organization has a Shared VPC setup where the host project contains several service projects. You need to configure a firewall rule that allows instances in the 'web-tier' subnet of the host project to communicate with instances in the 'app-tier' subnet of a specific service project. However, traffic should be restricted to TCP port 8080. What is the correct way to configure this firewall rule?

  1. A

    Create an ingress firewall rule in the host project with the source tag for 'web-tier' and destination tag for 'app-tier', allowing TCP port 8080.

  2. B

    Create an egress firewall rule in the host project that allows traffic from the 'web-tier' subnet to the 'app-tier' subnet on TCP port 8080.

  3. C

    Create an ingress firewall rule in the service project where the 'app-tier' subnet resides, allowing traffic from the 'web-tier' subnet of the host project on TCP port 8080.

  4. D

    Configure VPC peering between the host project and the service project to allow traffic between the 'web-tier' and 'app-tier' subnets.

  5. E

    Create an ingress firewall rule in the Shared VPC host project to allow TCP port 8080 traffic from the 'web-tier' subnet to the 'app-tier' subnet, using subnet IP ranges.

Show answer and explanation

Correct answers: B, E

Explanation

In a Shared VPC setup, all firewall rules are managed by the host project, as it owns the VPC network. To allow communication between subnets across projects, you can configure egress and ingress firewall rules in the host project. Egress rules permit traffic leaving a source subnet (e.g., 'web-tier'), while ingress rules permit traffic entering a destination subnet (e.g., 'app-tier'). Using IP ranges or subnets ensures precise control over traffic, and TCP port 8080 can be explicitly allowed in the rule configuration. Tags or VPC peering are not applicable in this scenario.

  • A. Incorrect.

    Incorrect. Tags cannot be used to reference subnets across projects, especially in a Shared VPC setup.

  • B. Correct.

    Correct. Egress firewall rules in the host project can allow traffic to service project subnets. Here, you would configure the egress rule to permit traffic on TCP port 8080 from the 'web-tier' subnet to the 'app-tier' subnet.

  • C. Incorrect.

    Incorrect. Firewall rules in service projects do not control traffic in Shared VPC setups. The host project manages all network configurations.

  • D. Incorrect.

    Incorrect. VPC peering is not required in Shared VPC setups, as the subnets already belong to the same network namespace.

  • E. Correct.

    Correct. Ingress firewall rules in the Shared VPC host project can allow traffic from specific subnet IP ranges, such as the 'web-tier' subnet, to the target subnet ('app-tier') on a specific port like TCP 8080.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam