🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 52 minutes remaining!

GCP Associate Cloud Engineer Practice Question

Your company has two Compute Engine instance groups in the same VPC: an app tier that runs with the service account "[email protected]" and a web tier that is tagged "web". Only the app-tier VMs and the on-premises CIDR block 10.50.0.0/16 should be able to reach TCP port 8080 on the web-tier instances; all other sources must be blocked. You learn that an ingress Cloud Next Generation Firewall (Cloud NGFW) rule can include only one kind of source filter (either service accounts, network tags, or IP ranges) per rule. What is the most operationally efficient way to meet the requirement?

  • Create one ingress rule that allows 0.0.0.0/0 to reach the web-tier service account on tcp:8080 and rely on IAM to restrict access.

  • Create two ingress rules that both target the "web" tag and allow tcp:8080: (1) a rule whose source service account is "[email protected]" and (2) a rule whose source IP range is 10.50.0.0/16.

  • Create a single ingress rule with source network tag "app" and IP range 10.50.0.0/16 targeting the "web" tag on tcp:8080.

  • Create a single ingress rule that lists both the source service account "[email protected]" and the source IP range 10.50.0.0/16, targeting the "web" tag on tcp:8080.

GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot