GCP Professional Cloud Security Engineer Practice Question
Your company detects malware on a production Compute Engine VM that successfully retrieves a service-account access token from the instance metadata server and then tries to upload it to random public IP addresses. The VM must remain online until the next maintenance window and still needs to reach Google Cloud APIs over Private Google Access (199.36.153.8/30). Which action provides an immediate, least-disruptive mitigation using only VPC firewall rules?
Create an egress deny rule that blocks traffic to 169.254.169.254/32 from the VM.
Apply two high-priority egress rules to the VM's network tag: first allow traffic to 199.36.153.8/30, then deny all remaining egress to 0.0.0.0/0.
Enable VPC Service Controls on the project to restrict data exfiltration for the VM.
Add an ingress deny rule on TCP port 80 for the VM to stop internet hosts from connecting.
VPC firewall rules filter traffic that leaves or enters a VM's virtual NIC. They cannot block the link-local metadata address (169.254.169.254), which is reached over the NIC's loopback path and therefore never evaluated by VPC firewalls. The practical control point is egress to external networks: prevent any destination except the Private Google Access IP range that the workload legitimately needs. Creating a very high-priority egress rule that allows traffic to 199.36.153.8/30 for the affected VM, followed by another high-priority rule that denies all remaining egress (0.0.0.0/0), stops the stolen token from leaving the VM while keeping calls to Google APIs functional. The other options either target traffic paths the firewall cannot control (metadata server), address inbound rather than outbound flows, or require additional services instead of the requested firewall-only fix.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are VPC firewall rules in GCP?
Open an interactive chat with Bash
What is Private Google Access, and why is it needed?
Open an interactive chat with Bash
Why can't VPC firewalls block the metadata server (169.254.169.254)?
Open an interactive chat with Bash
Why can't VPC firewall rules block traffic to the metadata server's IP address 169.254.169.254/32?
Open an interactive chat with Bash
What is Private Google Access, and why is 199.36.153.8/30 important in this solution?
Open an interactive chat with Bash
How do 'high-priority' firewall rules function in GCP VPC settings?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .