You created a custom-mode VPC network named prod-net for a new application. Two regional subnets exist: 10.10.0.0/24 in us-central1 and 10.20.0.0/24 in us-east1. Instances in each subnet have outbound internet connectivity but cannot ping each other over their internal IPs. You must enable all internal traffic between the subnets while keeping any incoming traffic from the internet blocked. Which single firewall rule should you create?
Create an egress firewall rule in prod-net that allows all protocols to 10.0.0.0/8 with priority 65534.
Create an ingress firewall rule in prod-net that allows all protocols from 0.0.0.0/0 with priority 1000.
Create an ingress firewall rule in prod-net that allows all protocols from 10.0.0.0/8 with priority 65534.
Create an egress firewall rule in prod-net that allows all protocols to 0.0.0.0/0 with priority 1000.
A custom-mode VPC starts with only the two implied rules: allow-egress (priority 65535) and deny-ingress (priority 65535). Because the deny rule applies to all ingress traffic, even packets whose source is another subnet in the same network are blocked. To enable internal communication you need an ingress rule that explicitly allows traffic whose source is the network's private address space (for example 10.0.0.0/8, which includes both subnets). Any priority number lower than 65535 overrides the implied deny rule; 65534 is sufficient. An egress rule is unnecessary because egress is already allowed, and using 0.0.0.0/0 as the source would open the network to the public internet.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a custom-mode VPC network in GCP?
Open an interactive chat with Bash
Why is an ingress rule required for internal communication within subnets?
Open an interactive chat with Bash
What does priority mean in a firewall rule, and why is it important?
Open an interactive chat with Bash
What is the difference between ingress and egress in VPC firewall rules?
Open an interactive chat with Bash
Why is allowing internal traffic between subnets restricted by default in a custom-mode VPC?
Open an interactive chat with Bash
What does the 10.0.0.0/8 address range represent in Google Cloud VPCs?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Setting up a cloud solution environment
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .