GCP Professional Cloud Security Engineer Practice Question
Your security team must inspect all outbound HTTPS traffic from production VMs for malware before it leaves the VPC. Using Google Cloud NGFW, you must (a) transparently decrypt, inspect, and re-encrypt TLS sessions with no VM changes, (b) block malicious flows, and (c) avoid hair-pin latency by keeping inspection distributed in-line rather than routing to a centralized appliance. Which configuration meets these requirements?
Create a network firewall policy that enables a TLS inspection policy and applies an Intrusion Prevention Service (IPS) rule set to egress traffic from the production subnet, then attach the policy to the VPC network.
Deploy a proxy VM with a third-party NGFW image and route the production subnet's default route to the proxy's internal IP address.
Add a high-priority egress firewall rule that ALLOWs tcp:443 from the production subnet to 0.0.0.0/0 and rely on Cloud Armor for inspection.
Enable VPC Flow Logs at the subnet level and configure log-based alerting to flag any egress connection that matches known malware IPs.
Cloud NGFW provides Layer-7 inspection through TLS interception combined with Intrusion Prevention Service (IPS) profiles. Creating a firewall policy that enables a TLS inspection policy and attaches an IPS security profile to egress rules causes the distributed service to decrypt, inspect, and re-encrypt HTTPS flows in-line at the regional endpoints. VMs need no proxy settings, benign traffic is forwarded, malicious flows are blocked, and no hair-pinning occurs. An ALLOW rule alone, VPC Flow Logs, Cloud Armor, or a proxy VM would not meet all three requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is TLS interception in Google Cloud NGFW?
Open an interactive chat with Bash
What is an Intrusion Prevention Service (IPS) in Google Cloud NGFW?
Open an interactive chat with Bash
Why is distributed in-line inspection better than using a centralized appliance?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .