GCP Professional Cloud Security Engineer Practice Question

Your company manages more than 60 projects inside a single Google Cloud organization. A new security mandate states that any egress packet destined for an IP address that appears in Google Cloud Threat Intelligence feeds must be blocked across every VPC network. Project administrators must not be able to alter or remove this control, but the central security team needs a simple way to grant one-off exceptions for individual projects that legitimately require access to a specific blocked IP address. Using Cloud Next Generation Firewall, what is the most scalable way to meet these requirements?

  • Deploy Secure Web Proxy in each VPC, block outbound access to the malicious IP list, and allow project owners to disable the proxy on subnets that require exceptions.

  • Configure identical egress deny rules that reference Threat Intelligence lists in every project's VPC firewall and ask project owners to request changes when they need exceptions.

  • Create a hierarchical firewall policy at the organization level managed by the security team. Add a deny-egress rule that uses Threat Intelligence IP lists with a lower priority number, and insert higher-priority allow rules scoped to specific project service accounts whenever an exception is approved.

  • Attach a Cloud Armor security policy with Threat Intelligence rules to each project's external HTTP(S) load balancer and let teams override the policy locally when necessary.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot