Your Shared VPC contains a bastion host whose VM service account is [email protected]. Backend instances that must be reached only through this bastion are labeled with the network tag internal-app. You need a single firewall configuration that permits SSH traffic from the bastion to the back-end VMs and blocks SSH from every other source. Which approach satisfies the requirement while minimizing ongoing administration effort?
Create an ingress rule that allows tcp:22 from the VPC's entire RFC 1918 range and targets the internal-app tag.
Add an egress rule on the bastion host that allows tcp:22 to the internal-app tag; rely on the default ingress rules for the rest.
Create one ingress firewall rule that allows tcp:22 with the bastion service account as the source and the target network tag internal-app.
Assign the network tag bastion to the bastion host and create an ingress rule that allows tcp:22 from the bastion tag to the internal-app tag.
A single ingress firewall rule that allows tcp:22 where the source is the bastion's service account and the targets are the tagged back-end instances meets the objective. Using the service account as the source scope limits the rule to exactly the bastion host, even if its IP changes, and using the tag as the target scope applies the rule only to the internal-app VMs. An IP-based rule would admit any host in that range, an egress rule would not protect the targets from other sources, and using source tags would require managing tags on every possible source VM, increasing operational overhead.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an ingress firewall rule in GCP?
Open an interactive chat with Bash
What are network tags in GCP?
Open an interactive chat with Bash
Why use service accounts as a source in firewall rules?
Open an interactive chat with Bash
What is a Service Account in GCP, and how does it function as a source in a firewall rule?
Open an interactive chat with Bash
What are network tags in GCP, and how are they applied to manage firewall rules?
Open an interactive chat with Bash
What is the difference between ingress and egress firewall rules in GCP?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .