GCP Professional Cloud Security Engineer Practice Question
Your security team needs to run SQL queries in Log Analytics to identify outbound HTTP requests that Cloud NGFW blocks as command-and-control traffic. You deployed a regional Cloud NGFW Standard tier with layer-7 inspection and enabled logging, but no threat-type entries appear in Cloud Logging. Without adding new third-party services, what change will allow the SOC to obtain the required threat logs?
Activate Event Threat Detection in Security Command Center and export its findings to Log Analytics for analysis.
Configure Packet Mirroring to feed traffic to Cloud IDS and query the resulting IDS alert logs in Log Analytics.
Migrate the regional Cloud NGFW to the Enterprise tier and enable intrusion prevention with threat logging on each firewall policy rule.
Enable Firewall Rules Logging on all VPC firewall rules and include full metadata to capture threat information.
Upgrading the deployment to Cloud NGFW Enterprise tier unlocks signature-based intrusion prevention and threat intelligence. After the upgrade, you must explicitly enable intrusion prevention and threat logging on each relevant firewall policy rule. Only then does Cloud NGFW generate threat-type log entries that Log Analytics can query. Firewall Rules Logging, Security Command Center's Event Threat Detection, or Cloud IDS either lack the necessary telemetry or add extra services and cost without making Cloud NGFW itself emit threat logs.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Cloud NGFW Enterprise tier, and how is it different from the Standard tier?
Open an interactive chat with Bash
What is intrusion prevention, and why is threat logging important in this scenario?
Open an interactive chat with Bash
How does Log Analytics process threat logs, and why does Cloud NGFW need to generate them?
Open an interactive chat with Bash
What is the Cloud NGFW Enterprise tier and how does it differ from the Standard tier?
Open an interactive chat with Bash
What is intrusion prevention and why is it essential for threat logging?
Open an interactive chat with Bash
Why can’t other services like VPC Firewall Rules Logging or Cloud IDS produce the required threat logs?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .