Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Professional Cloud Network Engineer Exam - Topic 2 Question 121 Discussion

Your company offers a popular gaming service. Your instances are deployed with private IP addresses, and external access is granted through a global load balancer. You believe you have identified a potential malicious actor, but aren't certain you have the correct client IP address. You want to identify this actor while minimizing disruption to your legitimate users.What should you do?
B) Create a Cloud Armor Policy rule that denies traffic, enable preview mode, and review necessary logs.
A) Create a Cloud Armor Policy rule that denies traffic and review necessary logs.
C) Create a VPC Firewall rule that denies traffic, enable logging and set enforcement to disabled, and review necessary logs.
D) Create a VPC Firewall rule that denies traffic, enable logging and set enforcement to enabled, and review necessary logs.

Google Professional Cloud Network Engineer Exam - Topic 2 Question 121 Discussion

Actual exam question for Google's Professional Cloud Network Engineer exam
Question #: 121
Topic #: 2
[All Professional Cloud Network Engineer Questions]

Your company offers a popular gaming service. Your instances are deployed with private IP addresses, and external access is granted through a global load balancer. You believe you have identified a potential malicious actor, but aren't certain you have the correct client IP address. You want to identify this actor while minimizing disruption to your legitimate users.

What should you do?

Show Suggested Answer Hide Answer
Suggested Answer: B

https://cloud.google.com/armor/docs/security-policy-concepts#preview_mode


Contribute your Thoughts:

0/2000 characters
Bong
3 hours ago
I think option B is the best choice. Preview mode is key!
upvoted 0 times
...
Angella
5 days ago
I recall that preview mode is important for testing changes. So, I lean towards option B, but I wonder if there are any risks with that approach.
upvoted 0 times
...
Ruby
10 days ago
I practiced a similar question where enabling logging was crucial. I feel like option D might be too aggressive since it enforces the rule immediately.
upvoted 0 times
...
Dianne
16 days ago
I'm not entirely sure, but I remember something about using VPC Firewall rules for more granular control. Maybe option C could be the way to go?
upvoted 0 times
...
Tom
2 months ago
I think option B makes sense because it allows us to test the rule without actually blocking legitimate users right away.
upvoted 0 times
...

Save Cancel