GCP Professional Cloud Security Engineer Practice Question
Your security team wants to replace a set of regional VM-based firewalls that currently hairpin all traffic through a few "choke point" instances. The new solution must keep filtering close to each workload, automatically scale to tens of Tbps without creating additional hops, and provide one place to apply advanced threat intelligence rules across all VPC networks. Which Google Cloud capability best meets these requirements?
Cloud Armor web application firewall in front of the existing firewalls
Deploy Cloud IDS sensors and use Packet Mirroring for threat detection
VPC firewall rules with manual instance tags in each subnet
Cloud Next Generation Firewall with hierarchical or network firewall policies
Cloud Next Generation Firewall is implemented inside Google's virtual networking data plane, so every packet that enters or leaves a VPC subnet is inspected at the point of ingress or egress-there is no need to route traffic through separate firewall appliances or gateways. Because enforcement is fully distributed, capacity scales automatically with Google's infrastructure and applies consistently across regions. Hierarchical and network firewall policies let administrators define a single set of rules, including threat-intelligence controls, that protect all selected VPCs. Traditional VPC firewall rules lack advanced threat intelligence, Cloud Armor protects only load-balanced (north-south) HTTP(S) traffic, and Cloud IDS relies on mirrored copies of traffic rather than in-path enforcement, so none of those options satisfy all stated requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Cloud Next Generation Firewall, and how does it differ from traditional VPC firewall rules?
Open an interactive chat with Bash
What are hierarchical and network firewall policies, and how do they improve security management?
Open an interactive chat with Bash
Why is Cloud IDS not suitable for replacing VM-based firewalls in this scenario?
Open an interactive chat with Bash
What is Google's virtual networking data plane?
Open an interactive chat with Bash
How do hierarchical and network firewall policies work in Google Cloud?
Open an interactive chat with Bash
What is the difference between Cloud IDS and the Cloud Next Generation Firewall?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .