GCP Professional Cloud Security Engineer Practice Question
Your company operates Compute Engine instances in a regional subnet behind a regional external HTTP(S) load balancer that terminates TLS. Regional Cloud NGFW network firewall policies already enforce Layer-4 rules on the VPC. The security team must detect and block Layer-7 exploits such as Log4Shell in real time, avoid adding proxy VMs or changing the load balancer, and preserve the existing regional policy hierarchy. Which approach satisfies these requirements?
Add an IPS threat prevention profile to the existing regional Cloud NGFW firewall policy rule that targets the API backend subnet, enabling automatic block mode for critical and high-severity signatures.
Enable Cloud NGFW threat intelligence deny lists on the policy to block known malicious IP addresses attempting to reach the API service.
Create a new VM-based proxy cluster running open-source Suricata, route all API traffic through the proxy, and manage Suricata signature updates manually.
Replace the regional network firewall policy with a new global policy that contains Layer-4 allow rules and rely on the external HTTP(S) load balancer's built-in WAF capabilities only.
Attach an IPS threat prevention profile to the existing regional Cloud NGFW firewall policy rule that matches traffic to the API back end. Cloud NGFW's Intrusion Prevention Service performs inline deep-packet inspection up to Layer 7 on Google-managed infrastructure and can block signatures for Log4Shell or command-injection attempts. Because TLS is terminated at the external HTTP(S) load balancer, the IPS analyzes plaintext HTTP without requiring additional proxy VMs or changes to the load balancer, while keeping the current regional policy structure. Other approaches either lack Layer-7 blocking or introduce extra operational overhead.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an IPS threat prevention profile in Cloud NGFW?
Open an interactive chat with Bash
How does Cloud NGFW perform Layer-7 threat detection?
Open an interactive chat with Bash
Why doesn't Cloud NGFW need proxy VMs for detecting Layer-7 threats?
Open an interactive chat with Bash
What is an IPS threat prevention profile?
Open an interactive chat with Bash
How does deep-packet inspection work in Cloud NGFW?
Open an interactive chat with Bash
Why is using Cloud NGFW better than adding proxy VMs for Layer-7 protection?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .