🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 31 minutes remaining!

GCP Associate Cloud Engineer Practice Question

Your custom-mode VPC hosts hundreds of VMs. Security sets two rules:

  1. Only VMs tagged "web" must accept TCP 443 from any IPv4 address.
  2. All VMs may send outbound traffic, except VMs tagged "restricted", which must not reach the public internet. You will meet both needs using one hierarchical Cloud NGFW policy attached to the VPC. Which set of firewall policy rules should you configure?
  • Ingress rule: allow tcp:443 from 0.0.0.0/0 to targets with tag "web" (priority 1000). Egress rule 1: allow all protocols to 0.0.0.0/0 from all instances (priority 900). Egress rule 2: deny all protocols to 0.0.0.0/0 from targets with tag "restricted" (priority 1000).

  • Ingress rule: deny all protocols from 0.0.0.0/0 to targets without tag "web" (priority 1000); allow tcp:443 from 0.0.0.0/0 to targets with tag "web" (priority 2000). Egress rule: allow all protocols to 0.0.0.0/0 from all instances (priority 1000).

  • Ingress rule: allow tcp:443 from 0.0.0.0/0 to targets with tag "web" (priority 1000). Egress rule: allow all protocols to 0.0.0.0/0 for all instances (priority 1000). Implicit deny will block restricted VMs on egress.

  • Ingress rule: allow tcp:443 from 0.0.0.0/0 to targets with tag "web" (priority 1000). Egress rule 1: deny all protocols to 0.0.0.0/0 from targets with tag "restricted" (priority 900). Egress rule 2: allow all protocols to 0.0.0.0/0 from all instances (priority 1000).

GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot