🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 30 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your company uses a Shared VPC in the prod-host project; three service projects attach their VM workloads to the shared "prod-vpc" network. Web-tier instances that must receive HTTPS traffic from partner IP range 203.0.113.0/24 all run as the IAM service account [email protected] and share subnets with other internal services that must remain inaccessible from the partner network. You need to create a single VPC firewall rule in the host project to meet the requirement while following least-privilege and minimizing future operational overhead. Which configuration will satisfy the goal?

  • Attach a network firewall policy to the shared subnet with a rule that allows 0.0.0.0/0 to tcp:443 for any target because stateful inspection will protect other workloads.

  • Create matching ingress and egress rules that allow tcp:443 between 203.0.113.0/24 and all instances tagged "web", then tag the required VMs.

  • Create an ingress firewall rule that allows tcp:443 from 203.0.113.0/24 and targets the subnet IP range; rely on the default priority.

  • Create an ingress firewall rule in prod-host that allows tcp:443 from 203.0.113.0/24, sets target service accounts to [email protected], and assigns a priority higher than the default deny.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot