GCP Professional Cloud Security Engineer Practice Question

A security engineer needs to feed Compute Engine VM traffic into Cloud IDS for threat detection. The VMs run in the prod-vpc network in europe-west1. To centralize inspection, the engineer created a Packet Mirroring policy that lists the VMs as sources and chooses an existing Cloud IDS endpoint deployed in us-central1 as the collector. No mirrored packets arrive at Cloud IDS and no firewall drops are observed. What change will allow the mirrored traffic to be delivered?

  • Replace the Cloud IDS collector with an internal TCP/UDP load balancer, because Cloud IDS endpoints cannot be used as Packet Mirroring collectors.

  • Create or select a Cloud IDS endpoint in europe-west1 and update the Packet Mirroring policy so the collector is in the same region as the mirrored VMs.

  • Enable VPC Flow Logs on prod-vpc, because Packet Mirroring forwards only traffic from subnets that have flow logs turned on.

  • Assign only internal IP addresses to the VMs; Packet Mirroring ignores interfaces that also have external IPs.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot