Your organization uses a Shared VPC named prod-net. All application servers run under the Compute Engine service account [email protected]. You need to build an ingress Cloud NGFW rule that permits SSH traffic from the on-premises management subnet only to these servers. The rule must automatically include any new VM that uses the same service account. What should you configure in the Targets field?
The primary internal IP range of the management subnet
A firewall rule that targets a specific service account is automatically applied to every existing or future VM instance that runs with that service account, regardless of the subnet or zone in which the VM resides. Using a network tag would require administrators to remember to tag every new instance, and targeting an IP range or the entire VPC would expose more resources than required. Therefore, specifying the service account in the Targets field meets the requirement of limiting the rule to the intended VMs while keeping administration effortless as new instances are created.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Shared VPC in GCP?
Open an interactive chat with Bash
What benefits does targeting a service account in firewall rules provide?
Open an interactive chat with Bash
How does Cloud NGFW work with GCP Compute Engine instances?
Open an interactive chat with Bash
What is a service account in Google Cloud?
Open an interactive chat with Bash
Why use a service account for firewall rules?
Open an interactive chat with Bash
What is a Cloud NGFW (Next-Generation Firewall)?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .