🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 50 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company's compliance team requires that all VM instances inside the prod-vpc are allowed to initiate outbound connections only to a short list of corporate SaaS providers whose hostnames may resolve to changing public IP addresses. You are using regional Cloud Next Generation Firewall because classic VPC firewall rules cannot express domain objects. Which configuration will most effectively enforce this requirement while minimizing operational effort when the SaaS providers rotate their IP ranges?

  • Publish the list of approved SaaS domains in an Organization-level hierarchical firewall policy so that all VPC networks inherit the same egress restriction.

  • Configure a Cloud NAT gateway for prod-vpc and restrict its allocated external IP addresses to the SaaS providers' address ranges.

  • Add egress VPC firewall rules in prod-vpc that specify the current public IP ranges of each SaaS provider and update them whenever the providers change their addresses.

  • Create a regional network firewall policy with egress rules that use FQDN objects for the approved SaaS hostnames, then attach the policy to the prod-vpc network.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot