GCP Professional Cloud Security Engineer Practice Question
Your security team is replacing a fleet of autoscaled third-party firewall virtual machines that currently sit behind an internal TCP/UDP load balancer. They are evaluating Google Cloud Next Generation Firewall (Cloud NGFW) to improve scalability and reduce network complexity. Which characteristic of Cloud NGFW directly removes the need for traffic hair-pinning through a centralized firewall appliance and enables line-rate inspection of both east-west and north-south traffic?
Only traffic that first reaches an external or internal load balancer is inspected; intra-VPC (east-west) flows bypass the service entirely.
It runs as a managed instance group of dedicated firewall VMs that all traffic must traverse via custom next-hop routes.
Packets are forwarded to a regional firewall service through static routes, introducing a single inspection point limited to 80 Gbps per region.
Firewall rules are enforced at each VM's virtual NIC, distributing inspection across Google's network fabric and eliminating any centralized choke point.
Cloud NGFW is implemented as a fully distributed service in Google's virtual networking stack. Enforcement happens at the virtual NIC of every Compute Engine VM (and other workload endpoints), so packets are filtered where they enter or leave each instance. Because inspection is performed locally on the host without requiring routes to a central firewall or load balancer, there is no hair-pinning, no single bottleneck, and the firewall scales automatically with workload growth. The other options describe legacy appliance-based or load-balancer-centric models that rely on forwarding all traffic to dedicated firewall instances, which Cloud NGFW is specifically designed to avoid.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does traffic hair-pinning mean?
Open an interactive chat with Bash
What is east-west and north-south traffic?
Open an interactive chat with Bash
How does enforcing rules at the virtual NIC improve scalability?
Open an interactive chat with Bash
What is Cloud NGFW in Google Cloud?
Open an interactive chat with Bash
What does 'traffic hair-pinning' mean in network security?
Open an interactive chat with Bash
What is the difference between north-south and east-west traffic in networking?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .