GCP Professional Cloud Security Engineer Practice Question

Your company runs several internal microservices in multiple GCP regions on a Shared VPC. Security policy requires that every outbound TLS connection those services initiate to the public internet be decrypted and inspected so malware uploads can be blocked based on application-layer signatures. The team does not want to deploy or manage host-based or explicit web proxies, and the solution must scale automatically in every current and future region. TLS decryption keys should be generated and rotated automatically by Google Cloud, without any customer-hosted key infrastructure. Which approach best meets these requirements?

  • Create an organization-level global network firewall policy, add an egress rule that uses a Cloud NGFW TLS inspection policy with Google-managed keys, enable the built-in intrusion-prevention service in blocking mode, and attach the policy to all Shared VPC networks.

  • Reroute all outbound traffic through an external HTTP(S) load balancer that terminates TLS with Google-managed certificates and apply a Cloud Armor web-application-firewall policy to block malicious uploads.

  • Enable Private Google Access and Cloud NAT, then add VPC firewall egress rules that deny connections to known malicious IP addresses based on threat-intelligence lists while allowing other destinations.

  • Deploy Secure Web Proxy in explicit mode, distribute a PAC file to every VM so egress traffic is forwarded through the proxy, and configure TLS interception using certificates issued by Certificate Authority Service.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot