🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 26 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your security team wants to block all ingress traffic coming from IP addresses that Google has classified as active command-and-control (C2) endpoints. You are using Cloud Next Generation Firewall (Cloud NGFW) hierarchical firewall policies for the entire organization. Which configuration should you implement to meet the requirement while minimizing ongoing operational effort?

  • Enable Cloud Armor's preconfigured malware rule at the HTTP(S) load balancer front end to filter requests from malicious sources.

  • Publish a custom list of known C2 addresses in Cloud Storage and reference it from an ingress firewall rule that logs but does not block matching traffic.

  • Create a regional egress firewall rule that denies traffic to the threat-intel.botnet destination IP match condition.

  • Add an organization-level ingress firewall policy rule that denies traffic with the threat-intel.c2 source IP match condition and apply it to all targets.

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot