🔥 40% Off Crucial Exams Memberships — Deal ends today!

46 minutes, 36 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization runs a multi-region application on Google Cloud. Each VPC network contains subnets in us-central1, europe-west1, and asia-southeast1. Security mandates that a single set of egress rules must block known malicious IP ranges and allow outbound HTTPS to partner networks, no matter which region a VM is in. At the same time, network engineers need the flexibility to add region-specific deny rules for legacy systems being phased out only in europe-west1. You plan to use Cloud Next Generation Firewall (Cloud NGFW). Which combination of firewall policy attachments best meets the requirements while minimizing rule duplication and operational overhead?

  • Attach a hierarchical firewall policy at the organization level for the common rules and another hierarchical policy at the folder level targeting europe-west1 projects.

  • Attach a regional firewall policy in every region for the common rules and another regional policy in europe-west1 for the legacy deny rules.

  • Attach a global network firewall policy to each VPC for the common rules and a regional firewall policy only in europe-west1 for the legacy deny rules.

  • Attach a single global network firewall policy that contains both the common rules and the europe-specific legacy deny rules, using target tags to scope the deny rules to europe-west1.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot