🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 53 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization hosts dozens of VPC networks spread across many projects. Security leadership has mandated that

  1. Any egress traffic destined for IP addresses contained in Google's Threat Intelligence feed must be blocked everywhere.
  2. Production VMs may initiate outbound connections only to a short allow-list of partner FQDNs; all other egress from production VMs must be denied.
  3. Development VMs must keep their current ability to reach the public internet for testing purposes.

You have these constraints:

  • Administration of individual projects is delegated to separate teams.
  • You must minimize ongoing operational overhead for security teams and avoid forcing project admins to re-create rules.
  • Future projects added under the same folder structure must inherit the protections automatically.

Which design best meets all requirements while respecting the principle of least privilege?

  • In every project, replace existing VPC firewall rules with identical sets that deny egress to malicious IPs, then create additional egress rules in each production VPC to allow partner FQDNs and deny all other destinations.

  • Create an organization-level Cloud NGFW firewall policy with a high-priority deny rule that references the Threat Intelligence "malicious IP" list, attach it to the organization node, and attach a second folder-level firewall policy to the production folder with higher-priority allow rules for the partner FQDNs followed by a deny-all; leave development projects without the folder-level policy.

  • Deploy separate regional Cloud NAT gateways for production and development; configure the production NAT gateway with custom route advertisements limited to partner IP ranges and leave development NAT open. Use no Cloud NGFW policies.

  • Enable Identity-Aware Proxy (IAP) for all VMs, require tunnelling outbound traffic through IAP TCP forwarding, and attach a single VPC firewall rule that denies traffic to malicious IPs at each project.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot