🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 52 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company runs a production VPC in the 10.0.0.0/16 range. VM instances that belong to the backend tier carry the network tag backend-svc. Only traffic coming from instances that have the network tag frontend-svc and that is destined for TCP port 8443 must reach the backend tier. All other ingress, including that currently allowed by the default allow-internal rule (priority 65534), must be blocked. Which set of two custom firewall rules satisfies the requirement?

  • Ingress allow rule: priority 1500, target tag backend-svc, source tag frontend-svc, TCP port 8443; and ingress deny rule: priority 1000, target tag backend-svc, source IP range 0.0.0.0/0, all protocols.

  • Single egress deny rule: priority 1000, target tag backend-svc, destination IP range 0.0.0.0/0, all protocols, relying on implicit ingress deny for other traffic.

  • Ingress allow rule: priority 1000, target tag backend-svc, source tag frontend-svc, TCP port 8443; and ingress deny rule: priority 1500, target tag backend-svc, source IP range 0.0.0.0/0, all protocols.

  • Single ingress allow rule: priority 1000, target tag backend-svc, source IP range 0.0.0.0/0, TCP port 8443, relying on the implicit deny rule for other packets.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot