Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Professional Cloud Network Engineer Exam - Topic 2 Question 121 Discussion

Your company offers a popular gaming service. Your instances are deployed with private IP addresses, and external access is granted through a global load balancer. You believe you have identified a potential malicious actor, but aren't certain you have the correct client IP address. You want to identify this actor while minimizing disruption to your legitimate users.What should you do?
B) Create a Cloud Armor Policy rule that denies traffic, enable preview mode, and review necessary logs.
A) Create a Cloud Armor Policy rule that denies traffic and review necessary logs.
C) Create a VPC Firewall rule that denies traffic, enable logging and set enforcement to disabled, and review necessary logs.
D) Create a VPC Firewall rule that denies traffic, enable logging and set enforcement to enabled, and review necessary logs.

Google Professional Cloud Network Engineer Exam - Topic 2 Question 121 Discussion

Actual exam question for Google's Professional Cloud Network Engineer exam
Question #: 121
Topic #: 2
[All Professional Cloud Network Engineer Questions]

Your company offers a popular gaming service. Your instances are deployed with private IP addresses, and external access is granted through a global load balancer. You believe you have identified a potential malicious actor, but aren't certain you have the correct client IP address. You want to identify this actor while minimizing disruption to your legitimate users.

What should you do?

Show Suggested Answer Hide Answer
Suggested Answer: B

https://cloud.google.com/armor/docs/security-policy-concepts#preview_mode


Contribute your Thoughts:

0/2000 characters
Lyda
4 days ago
Option A seems too risky without preview mode.
upvoted 0 times
...
Derick
9 days ago
Wait, can we really trust the logs to identify the actor?
upvoted 0 times
...
Dacia
14 days ago
I disagree, D seems safer with enforcement enabled.
upvoted 0 times
...
Alonso
19 days ago
I think option B is the best choice. Preview mode is key!
upvoted 0 times
...
Annalee
24 days ago
Just use option C if you want to play it safe!
upvoted 0 times
...
Mel
29 days ago
I like option A, but it feels a bit risky without preview mode.
upvoted 0 times
...
Lashonda
1 month ago
Wait, can we really trust the logs? They can be misleading sometimes.
upvoted 0 times
...
Evelynn
1 month ago
I disagree, option D seems more secure with enforcement enabled.
upvoted 0 times
...
Bong
1 month ago
I think option B is the best choice. Preview mode is key!
upvoted 0 times
...
Angella
2 months ago
I recall that preview mode is important for testing changes. So, I lean towards option B, but I wonder if there are any risks with that approach.
upvoted 0 times
...
Ruby
2 months ago
I practiced a similar question where enabling logging was crucial. I feel like option D might be too aggressive since it enforces the rule immediately.
upvoted 0 times
...
Dianne
2 months ago
I'm not entirely sure, but I remember something about using VPC Firewall rules for more granular control. Maybe option C could be the way to go?
upvoted 0 times
...
Tom
4 months ago
I think option B makes sense because it allows us to test the rule without actually blocking legitimate users right away.
upvoted 0 times
...

Save Cancel