GCP Professional Cloud Security Engineer Practice Question

Your security team wants to replace a set of regional VM-based firewalls that currently hairpin all traffic through a few "choke point" instances. The new solution must keep filtering close to each workload, automatically scale to tens of Tbps without creating additional hops, and provide one place to apply advanced threat intelligence rules across all VPC networks. Which Google Cloud capability best meets these requirements?

  • Deploy Cloud IDS sensors and use Packet Mirroring for threat detection

  • Cloud Armor web application firewall in front of the existing firewalls

  • Cloud Next Generation Firewall with hierarchical or network firewall policies

  • VPC firewall rules with manual instance tags in each subnet

GCP Professional Cloud Security Engineer
Securing communications and establishing boundary protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot