🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 27 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your security team must prevent any Compute Engine VM in any Google Cloud project from initiating outbound connections to IP addresses that Google's threat-intelligence service classifies as botnet command-and-control. At the same time, development teams occasionally need to make temporary, tightly scoped exceptions for a few VMs, which they identify with a special network tag. You want a solution that applies automatically to every current and future VPC network in the organization and minimizes ongoing operational work. Which implementation best meets these requirements?

  • Create a global network firewall policy at the organization node. Add an egress allow rule with a high precedence that matches only VMs tagged c2c-exempt, followed by a lower-precedence deny rule whose match condition is threatIntelligence:botnet-cnc. Attach the policy to all VPC networks in the organization so it is inherited by current and future projects.

  • Configure a Cloud Armor security policy that blocks traffic from botnet-classified source IPs and attach it to a shared external HTTP(S) load balancer that all outbound traffic must traverse; allow exceptions by letting teams bypass the load balancer.

  • Create an organization-level hierarchical firewall policy with a single egress deny rule for threatIntelligence:botnet-cnc at priority 100, and let project administrators create higher-priority allow rules in their own project-level firewall policies when they need exceptions.

  • Manually add a black-hole static route for every botnet command-and-control subnet to each VPC. Instruct teams to delete the route when they need an exception for specific VMs.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot