🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 57 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company has several Google Cloud projects grouped under a Dev folder. A new compliance control states that every VPC in that folder must deny all egress traffic by default, permit only HTTPS access to *.gcr.io and metadata.googleapis.com for image pulls and OS updates, and automatically block any connection whose destination IP appears on Google-maintained threat-intelligence lists. What is the most efficient way to meet these requirements with minimal ongoing operational effort?

  • Enable Identity-Aware Proxy for all workloads and create a VPC Service Controls perimeter that only allows access to gcr.io; rely on these services to satisfy the new egress restrictions.

  • Deploy a shared VPC with a Cloud NAT gateway restricted to port 443 and use Cloud DNS policies to block unwanted domains while relying on default VPC firewall rules for egress control.

  • Create a global Cloud NGFW policy and attach it to the Dev folder; set the default egress action to deny, add FQDN allow rules for *.gcr.io and metadata.googleapis.com, and enable Threat Intelligence blocking in the same policy.

  • Configure identical VPC firewall rules in every project: one egress deny rule for 0.0.0.0/0, two allow rules for the required domains, and apply Cloud Armor security policies to each VM to block malicious IPs.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot