GCP Professional Cloud Architect Practice Question

Your security team must add network-based threat detection to a group of Google Cloud projects that host external web applications behind global external HTTP(S) load balancers and several internal microservices that communicate across VPC peered networks. The solution must

  • detect known malware, command-and-control activity, and lateral movement in both north-south (internet-facing) and east-west (VPC-to-VPC) traffic,
  • be fully managed and kept current by the provider, leveraging industry-standard threat signatures,
  • avoid adding latency or changing the routing path for production packets, and
  • automatically surface high-fidelity findings in Security Command Center without additional tooling. Which architecture best meets all of these requirements?
  • Enable VPC Flow Logs at 100 percent sampling, export logs to Cloud Logging, and build log-based metrics with Cloud Monitoring alerts for suspicious patterns across all VPC networks.

  • Attach Cloud Armor web application firewall policies and Adaptive Protection to all external HTTP(S) load balancers and rely on its threat intelligence feeds for both north-south and east-west traffic inspection.

  • Create Cloud IDS endpoints in each required region, configure Packet Mirroring in every relevant subnet and load balancer backend to mirror traffic to the endpoints, and rely on Cloud IDS's native integration with Security Command Center for alerting.

  • Provision Suricata IDS instances behind an internal TCP load balancer and update subnet routes so that all application and inter-service traffic is forced through the Suricata tier before reaching its destination.

GCP Professional Cloud Architect
Managing and provisioning a solution infrastructure
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot