🔥 40% Off Crucial Exams Memberships — Deal ends today!

3 hours, 1 minute remaining!

GCP Associate Cloud Engineer Practice Question

Your security team must ensure that only the Compute Engine bastion host, which runs under the service account [email protected], can initiate SSH sessions to virtual machines that are part of the front-end tier in your custom VPC. All front-end VMs already have the network tag web. Which Cloud Next Generation Firewall rule definition satisfies the requirement while following least-privilege best practices?

  • Ingress rule - action allow; source: service account [email protected]; targets: network tag web; protocol/port: tcp:22

  • Ingress rule - action allow; source: 0.0.0.0/0; targets: service account [email protected]; protocol/port: tcp:22

  • Ingress rule - action deny; source: bastion host external IPv4 address; targets: network tag web; protocol/port: tcp:22

  • Egress rule - action allow; destination: service account [email protected]; targets: network tag web; protocol/port: tcp:22

GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot