Be able to map a threat scenario to the right Google Cloud control: Cloud Armor WAF rules for L7 attacks, Cloud NGFW and firewall policies for L3/L4, Cloud IDS for deep packet inspection, and PSC or VPC Service Controls for private segmentation. The key is attaching each control at the correct layer.
Start practicing
Configuring Network Security — choose a session length
Free · No account required
Domain overview
This domain covers designing and implementing network security on Google Cloud: VPC firewalls, Cloud Armor, Cloud NGFW, Private Service Connect, VPC Service Controls, and load balancer security. Questions present a scenario and ask you to select the correct service, rule type, or configuration to detect, block, or segment traffic.
Exam objectives
Selecting Cloud Armor security policies, preconfigured WAF rules, and Adaptive Protection for L7 DDoS and web attacks
Configuring VPC firewall rules, hierarchical firewall policies, and Cloud NGFW for stateful inspection and threat prevention
Using Cloud IDS for deep packet inspection to detect malware and command-and-control traffic in a VPC
Applying Private Service Connect, VPC Service Controls, and Shared VPC to enforce network segmentation and private access
Confusing Cloud Armor (L7, load balancer-attached) with Cloud NGFW or VPC firewall rules (L3/L4), leading to wrong service selection for the scenario.
Assuming Adaptive Protection auto-blocks malicious IPs; you must configure a security policy rule that references the adaptive protection signals to deny or throttle.
Forgetting that Cloud Armor policies attach to external HTTP(S) load balancers, not to internal VPC traffic or backend VMs directly.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A security engineer needs to restrict access to Cloud Storage buckets so that only resources in a specific VPC can reach the Google APIs. Which Google Cloud service should be used?
2An organization wants to enforce a security policy that denies all egress traffic to the internet from all projects in the organization, except for traffic from a specific set of VMs tagged with 'allow-egress'. Which approach should be used?
3A company uses VPC Service Controls to protect a BigQuery dataset. They need to allow an external on-premises application to query the dataset without being inside the service perimeter. The external application has a static IP address. Which configuration is required?
4An engineer needs to block a specific IP address from accessing an HTTPS load balancer. Which Cloud Armor rule should be used?
5A company wants internal VMs to access Google APIs (e.g., Cloud Storage, BigQuery) without traversing the internet. What is the simplest configuration?
6An organization uses VPC Service Controls in dry-run mode for a project containing Google Cloud Storage. They notice that BigQuery jobs are being logged as violations. How should they interpret this?
7Which Cloud Armor feature uses machine learning to detect and mitigate DDoS attacks?
8A service provider wants to expose an internal service to external consumers in a controlled manner, without giving them direct access to the VPC. Which Google Cloud service should be used?
9An organization wants to implement a zero-trust network security model for their Google Cloud environment. Which TWO practices should they adopt? (Choose TWO.)
10An organization uses VPC Service Controls to protect BigQuery datasets. They need to allow a specific on-premises application, which uses a static IP address, to query a BigQuery dataset inside the service perimeter. Which configuration is required?
11A web application behind an HTTPS load balancer is experiencing a high volume of malicious requests with SQL injection patterns. The security team wants to block these requests with minimal latency impact. Which Cloud Armor feature should they use?
12An organization uses a global HTTPS load balancer with a Google-managed SSL certificate. The certificate was automatically provisioned and renewed. Recently, the certificate renewal failed and the site shows a warning. The load balancer's frontend uses the certificate. What is the most likely cause?
13A security engineer needs to monitor network traffic for potential threats in a VPC. They want to inspect all traffic for malware signatures and alert on high-severity threats. The solution should be natively integrated with GCP. Which service should they use?
14A company wants to enforce that traffic between two projects in the same organization must go through a central inspection VPC. They need a firewall rule that denies all traffic between the projects except through the inspection VPC. Which type of firewall rule should they use?
15A company has a global HTTPS load balancer and wants to use a self-managed SSL certificate. They have uploaded the PEM-encoded certificate and private key to the load balancer. However, the certificate is about to expire. What is the correct way to renew it without downtime?
16A security team wants to block all incoming traffic from a specific country to their web application behind a global HTTPS load balancer. They also need to allow traffic from all other countries. Which Cloud Armor feature should be used?
17A security team wants to enforce SSL/TLS best practices for their HTTPS load balancer. They need to require TLS 1.2 or higher and restrict ciphers to strong ones only. Which TWO actions should they take? (Choose two.)
18An organization wants to restrict access to Google Cloud APIs such as BigQuery and Cloud Storage so that only requests originating from a specific VPC network are allowed. Which Google Cloud service should they use?
19A security team needs to apply a set of firewall rules that enforce baseline security for all VPC networks across multiple projects in an organization. These rules must be inherited and cannot be overridden by project-level rules. What should they use?
20An engineer wants to allow egress traffic from a group of VM instances with a specific service account to a set of IP addresses. They need to choose between using tags or service accounts as targets in a VPC firewall rule. Which approach is recommended for better security and why?
21An organization wants to provide private, on-premises access to Google Cloud APIs (e.g., Cloud Storage, BigQuery) without traversing the public internet. They have a Direct Connect link to Google Cloud. Which solution should they implement?
22A company wants to automatically provision and renew SSL certificates for their HTTPS load balancer. They want Google to manage the certificate lifecycle. Which certificate type should they use?
23A company is using Cloud Armor with adaptive protection enabled. They notice that adaptive protection has generated a rule that is blocking some legitimate traffic. What should they do to minimize false positives while still benefiting from adaptive protection?
24An organization has multiple VPC networks in different projects. They need to centrally manage firewall rules that apply to all VPCs in the organization and ensure that project owners cannot override them. Which solution should they use?
25A security team is configuring Cloud Armor to protect a web application. They need to block requests that contain SQL injection patterns, block requests from a known malicious IP list, and limit requests from any single IP to 2000 requests per minute. Which THREE actions must they take? (Choose three.)
26A security engineer wants to restrict access to a Cloud Storage bucket so that only requests originating from within a specific VPC network can access the bucket. Which Google Cloud service should they use?
27A company wants to use Cloud Armor Managed Protection Plus to protect their HTTP(S) load balancer from DDoS attacks. They need to automatically block traffic from IP addresses that exhibit anomalous behavior based on machine learning. Which Cloud Armor feature should they enable?
28An engineer needs to ensure that only VMs with a specific service account (sa-prod@project.iam.gserviceaccount.com) can access a Cloud Spanner instance. They want to control this at the network level, not using IAM. Which VPC firewall rule configuration should they use?
29A company wants to automatically provision and renew SSL certificates for their HTTPS load balancer. They do not want to manually manage certificate files. Which approach should they use?
30A security team needs to apply a security policy that blocks requests to their HTTP load balancer from a specific geographic region (e.g., Country A). Which Cloud Armor feature should they use?
31An organization uses VPC Service Controls to protect BigQuery. They want to test a new access level that allows access only from a specific IP range before enforcing it. Which mode should they use?
32A company has multiple VPCs in different projects that need to privately connect to a common internal service (e.g., a managed database) running in a central project. They want to expose this service via Private Service Connect. Which type of PSC endpoint should the consumer VPCs create?
33A DevOps engineer wants to use Cloud Armor to block common web application attacks like SQL injection and cross-site scripting. Which feature should they enable?
34A security engineer is configuring a VPC Service Controls perimeter to protect a Cloud Storage bucket. They want to allow a specific on-premises network (IP range 203.0.113.0/24) to access the bucket, while still blocking other external networks. Which TWO components must they configure? (Choose TWO.)
35A company wants to use Cloud IDS to detect threats in their VPC. They have created a Cloud IDS endpoint and need to configure packet mirroring. Which TWO resources must be in place for packet mirroring to work? (Choose TWO.)
36An organization wants to enforce that all Compute Engine instances in a project have a specific tag (e.g., 'env=prod') before they can be created. Which approach should be used?
37An organization wants to allow only specific trusted IP ranges to access a web application behind a Cloud Load Balancer. Which Cloud Armor feature should be used?
38Which GCP service provides managed intrusion detection by analyzing mirrored network traffic and using threat signatures from Palo Alto Networks?
39A company wants to enforce that no Compute Engine firewall rule in any project under an organization can have a source range of 0.0.0.0/0 for RDP (port 3389). Which approach should be used?
40An engineer needs to allow HTTP traffic from instances tagged 'web-server' to instances tagged 'app-server' on port 8080 within the same VPC. Which firewall rule should be created?
41Which feature of Cloud Armor uses machine learning to detect and block distributed denial-of-service (DDoS) attacks?
42An organization uses Certificate Manager to provision SSL certificates for multiple domains across several load balancers. They want to automate certificate renewal. Which type of certificate should be used?
43A company wants to prevent data exfiltration by restricting access to Google APIs from only authorized VPC networks. They also need to allow a specific on-premises IP range to access BigQuery. Which TWO services should be used together? (Choose 2)
44A company wants to restrict access to Cloud Storage buckets so that only resources in a specific VPC network can reach them, and data cannot be exfiltrated to other networks. Which Google Cloud service should they use?
45An organization has a hub-and-spoke VPC setup with Shared VPC. The security team wants to enforce a rule that all egress traffic from any project in the organization must pass through a central inspection appliance in the hub VPC. Which firewall configuration approach meets this requirement?
46A company wants to expose an internal web service running on a private GKE cluster to other services within the same VPC network using a private IP address. They do not want to use a public load balancer. Which Google Cloud service should they use?
47A security engineer needs to block traffic from all IP addresses in a specific geographic region from reaching an HTTPS load-balanced application. The application uses Cloud Load Balancing with an external HTTPS load balancer. Which approach should the engineer use?
48A company wants to use a Google-managed SSL certificate for their external HTTPS load balancer. Which step is required to provision the certificate?
49A company uses Cloud Armor Managed Protection Plus to protect their applications. They want to automatically block IP addresses that are identified as malicious by adaptive protection. How should they configure this?
50An organization needs to enforce a TLS minimum version of 1.2 for all traffic to their HTTPS load balancers. They have multiple load balancers serving different domains. Which Google Cloud feature should they use?
51A security team wants to detect and block network-based threats such as malware and command-and-control traffic within their VPC. They need a managed service that provides deep packet inspection. Which Google Cloud service should they use?
52A company has a VPC Service Controls perimeter that includes BigQuery and Cloud Storage. They need to allow a specific on-premises application (with a static IP) to access a BigQuery dataset within the perimeter. Which configuration should they use?
53A company uses Cloud Armor to protect a web application. They want to block requests that contain SQL injection patterns based on the OWASP ModSecurity Core Rule Set. Which preconfigured rule set should they enable?
54A company is designing a secure multi-tenant environment in Google Cloud. Each tenant has its own VPC network and resources. The security team wants to centrally enforce a rule that denies all egress traffic to the internet from tenant VPCs, except for traffic to specific trusted IP ranges for software updates. They also want to ensure that tenant admins cannot override this rule. Which two actions should they take? (Choose two.)
55A company is deploying a web application behind an external HTTPS load balancer. They want to protect against common web attacks such as XSS, SQLi, and LFI using preconfigured rules. They also need to allowlist specific IP addresses that belong to partners. Which three Cloud Armor features should they use? (Choose three.)
56An organization wants to restrict access to Google Cloud APIs such as BigQuery and Cloud Storage so that only resources within a specific VPC network can call these APIs, and no traffic from other VPCs or on-premises networks is allowed. Which Google Cloud service should they use?
57A security engineer needs to configure firewall rules to allow traffic from a set of compute instances to a set of backend instances. The engineer wants to use a method that is more secure and scalable than using network tags. Which approach should they use?
58A company wants to allow users from a specific on-premises IP range to access a service deployed on Google Cloud, but only if the user's device is compliant with corporate security policies (e.g., has antivirus enabled). Which combination of services can achieve this?
59A company wants to use a Google Cloud load balancer with an SSL certificate that is automatically provisioned and renewed. Which type of certificate should they use?
60A security engineer needs to block traffic to a set of VMs from specific IP addresses and also apply rate limiting for HTTP traffic. The VMs are behind a global external HTTPS load balancer. Which service should they use?
61A company wants to provide private connectivity from its on-premises network to Google Cloud APIs (e.g., BigQuery, Cloud Storage) without traversing the public internet. They have an existing Dedicated Interconnect connection. Which solution should they use?
62An organization has a hierarchical firewall policy at the organization level that denies all ingress traffic from the internet. A project team needs to allow HTTP traffic from the internet to a specific VM. How should they achieve this?
63A company wants to detect and alert on potential network threats, such as malware and command-and-control traffic, within their VPC. They need a managed service that integrates with packet mirroring. Which Google Cloud service should they use?
64A company's security policy requires that all traffic to a Google Cloud load balancer use TLS 1.2 or higher and only accept strong ciphers. They want to enforce this using a Google Cloud resource. Which resource should they configure?
65A company wants to use Private Service Connect to publish a managed service (e.g., a custom application) so that consumers can access it privately within Google Cloud. Which THREE resources are involved in this setup?
66Your organization uses Cloud Armor to protect HTTP Load Balancers. You need to block all incoming requests from a specific geographic region (country code 'XY') while allowing all other traffic. What is the correct configuration?
67You manage a Google Cloud environment using shared VPC with multiple service projects. You need to enforce consistent firewall rules across all projects in the organization, ensuring that certain security rules cannot be overridden by project administrators. Which TWO steps should you take? (Choose 2)
68A company's security team wants to inspect all egress traffic from their Google Cloud VPC to the internet for malware and data exfiltration. They need to ensure that traffic from a specific subnet is first inspected by a third-party firewall appliance deployed on a Compute Engine instance before it reaches the internet. The solution must be centrally managed and support high availability. What should they configure?
69A security engineer is configuring a Shared VPC in Google Cloud. The host project contains a subnet named 'prod-subnet' (10.0.1.0/24) in us-central1. A service project has a Compute Engine instance that must communicate with an on-premises database at 192.168.100.0/24 over a Cloud VPN tunnel. The engineer needs to ensure that return traffic from the on-premises database is routed back to the service project instance. What should the engineer do?
70A security engineer is configuring a VPC Service Controls perimeter to protect a sensitive BigQuery dataset. They need to allow a specific on-premises application to access the dataset using a VPN connection. The on-premises application uses a service account to authenticate. What should they do to allow this access while keeping the perimeter secure?
71A security engineer needs to allow SSH access to a Compute Engine instance from a specific on-premises IP range (203.0.113.0/24) only when the user's device is compliant with corporate policy. The company uses BeyondCorp Enterprise and has an Identity-Aware Proxy (IAP) setup. The engineer wants to enforce device compliance without exposing the instance to the internet. What should the engineer do?
72A security team needs to inspect outbound traffic from a VPC to detect and block malicious domains before it leaves the Google Cloud network. They want to enforce the policy centrally and avoid managing individual instance firewalls. Which Google Cloud service should they use?
73A company is deploying a web application on Compute Engine instances behind an external HTTP(S) load balancer. They want to protect the application from common web attacks such as SQL injection and cross-site scripting, and also mitigate denial-of-service attacks. They need to implement a solution that allows granular control based on request attributes. Which two Google Cloud services should they use? (Choose two.)
74A company is deploying a VPC Service Controls perimeter to protect sensitive data in BigQuery and Cloud Storage. They need to allow a specific on-premises application to access these services through a Cloud VPN tunnel. The application runs on a server with IP 198.51.100.10. Which two configurations are required to permit this access while maintaining the perimeter? (Choose two.)
75A security engineer needs to ensure that all traffic between two subnets in the same VPC network is logged for auditing purposes. They want to capture details such as source and destination IP addresses, ports, and protocol. What should they enable?
76A security engineer needs to ensure that all outbound traffic from a Compute Engine instance to the internet goes through a specific set of IP addresses for auditing. The instance is in a subnet with no external IP addresses. What should the engineer configure?
77A security engineer must ensure that only the production service account can access a Compute Engine VM's SSH port (22) from a specific subnet, while all other traffic is blocked. The VM's VPC has several subnets and firewall rules. Which approach should the engineer use to meet this requirement with least privilege?
78A security engineer manages a Shared VPC in Google Cloud. A team in a service project runs a three-tier web application on Compute Engine. The security team requires that instances in the web tier can receive HTTP/HTTPS traffic from the internet, but the database tier must only accept connections from the web tier on TCP port 5432. All instances are in the same Shared VPC network, and each tier is identified by a network tag. Which configuration should the engineer implement to meet these requirements?
79A company uses Shared VPC. The host project contains a subnet in us-central1. A service project has a VM that needs to reach an on-premises database via Cloud VPN. The security engineer must ensure that the VM's traffic to the on-premises CIDR is allowed and that return traffic is permitted. Which firewall rule should be created in the host project?
80A company uses Cloud VPN to connect its on-premises network to a Google Cloud VPC. The security team wants to ensure that all traffic from on-premises to Google Cloud is encrypted and that the on-premises router can dynamically learn routes from the VPC. They also want to minimize configuration overhead. Which Cloud VPN configuration should they use?
81A security engineer must allow SSH access to a set of Compute Engine VMs from a fixed set of corporate office public IP addresses. The VMs have no external IP addresses and are in a single VPC network. The engineer wants a reusable, centrally managed rule that is applied to all current and future VMs in the network. What should the engineer do?
82A security engineer is deploying a three-tier web application in a single Google Cloud VPC. The database tier must accept connections only from the application tier on TCP port 5432, and the application tier must accept HTTPS traffic only from the web tier. No other internal traffic should reach these tiers. The engineer wants the rules to remain effective even if new VM instances are added to each tier. What should the engineer do?
83A company uses Shared VPC. The host project contains a subnet with secondary IP ranges for GKE pods and services. A security engineer must ensure that pods in the service project can only reach a specific on-premises CIDR through a Cloud VPN tunnel, and that all other egress is blocked. What should they do?
84A security engineer is configuring a Shared VPC in Google Cloud. The host project contains a subnet named 'prod-subnet' in us-central1 with secondary ranges for GKE pods and services. A service project needs to deploy a GKE cluster that uses this subnet. The engineer must ensure that the GKE cluster's pods can communicate with each other and with services, but no other service project should be able to use this subnet. What should the engineer do?
85A company runs a Shared VPC host project with several service projects. Security requires that all egress traffic from service project workloads to external IP addresses be inspected by a centralized third-party appliance before leaving the VPC. The appliance is deployed in the host project and must see traffic from all service projects. Which approach should the security engineer use?
86A security engineer is configuring Identity-Aware Proxy (IAP) to protect an internal web application running on a Compute Engine instance group. The application should only be accessible to users in the 'security-team@example.com' Google Group, and only from company-managed devices. The engineer has already set up the IAP-secured resource and granted the group the 'IAP-secured Web App User' role. What additional configuration is required to enforce the device policy?
87A security engineer is configuring a Shared VPC in Google Cloud. The host project contains a VPC network with subnets, and several service projects are attached. The engineer needs to allow a specific service project's resources to communicate with on-premises systems over a Cloud VPN tunnel that terminates in the host project. The engineer has already created the VPN tunnel and added the on-premises routes to the host project's VPC. However, resources in the service project cannot reach the on-premises network. What is the most likely cause?
88A security engineer must ensure that all egress traffic from a Compute Engine instance is inspected by a third-party firewall appliance before reaching the internet, and that the instance cannot bypass the appliance. The instance and appliance are in the same VPC. What should they configure?
89A company has a VPC Service Controls perimeter that includes Cloud Storage and BigQuery. They need to allow a specific on-premises application to access these services using a dedicated Interconnect connection. The on-premises application uses a service account. What should they configure to allow access while maintaining the perimeter?
90A security engineer is configuring Cloud VPN to connect an on-premises network to a Google Cloud VPC. The on-premises VPN gateway supports only IKEv2 and requires a route-based VPN. The engineer must ensure that traffic from on-premises can reach specific VM instances in the VPC, and that the VPN tunnel is highly available. Which configuration should the engineer use?
91A company needs to allow its on-premises data center to reach internal Compute Engine instances over a private connection. They have set up Cloud Interconnect and want to ensure that traffic from the on-premises CIDR 10.10.0.0/16 can reach VMs in a subnet 10.0.1.0/24 on TCP port 443, but no other on-premises traffic should be allowed. They also want to avoid exposing the VMs to the internet. What should they do?
92A company has a Shared VPC setup where the host project contains a VPC network, and service projects contain VM instances. A security engineer needs to create a firewall rule in the host project that allows SSH access from a specific CIDR range to all VM instances in the service projects. The engineer wants to ensure that the rule applies only to instances with a specific network tag. What should the engineer do?
93A security engineer needs to allow outbound SSH (TCP port 22) from a subnet's Compute Engine instances to a specific external IP range, while denying all other outbound internet traffic. The VPC has a default route to the default internet gateway. Which firewall rule configuration should the engineer use?
94A security engineer needs to provide a group of contractors with access to a web application running on a private Compute Engine instance. The contractors connect from various locations on the internet, and the company does not want to expose the application's private IP address or manage a VPN for them. The application uses HTTPS on port 443. What should the engineer implement?
95A company has a VPC with two subnets in different regions. They want to ensure that a specific set of Compute Engine instances can only send traffic to the internet through a Cloud NAT gateway, and that no instance can receive unsolicited inbound traffic from the internet. They have already configured Cloud NAT on a Cloud Router in the region of the instances. Which additional configuration is needed to prevent unsolicited inbound traffic?
96A company wants to protect its external HTTP(S) load balancer from volumetric DDoS attacks and application-layer attacks. They need to use Google Cloud's advanced DDoS protection and WAF capabilities. Which service should they enable?
97A company wants to control which Google Cloud services its employees can access from corporate-managed devices on the corporate network. The security team wants to enforce that only approved services are reachable, and they want the policy to apply to all users on the network without installing software on each device. Which Google Cloud feature should they use?
98A security engineer needs to allow SSH access to a Compute Engine VM running in a VPC, but only from a specific bastion host in the same VPC. The bastion host has IP address 10.0.1.5. The VM is in subnet 10.0.2.0/24. The engineer wants to minimize the attack surface and ensure that only the bastion can initiate SSH connections to the VM. Which firewall rule should the engineer create?
99A security engineer is configuring Cloud Armor security policies for an external HTTP(S) load balancer. They need to protect against application-layer attacks and also ensure that only requests from specific countries are allowed. (Choose two.)
100A security engineer is designing a Shared VPC where a central host project provides subnets to multiple service projects. The requirement is that each service project's VMs can reach only the resources in their own project, and no service project may open firewall rules that affect the host project's network. What should the engineer configure?
101A company uses a Shared VPC where the host project contains subnets shared with multiple service projects. A security engineer must ensure that a specific service project's VM instances can only initiate connections to on-premises resources over Cloud VPN, and cannot reach other service projects' VMs. Which configuration should the engineer implement?
102A security engineer is setting up a VPC network in Google Cloud. The engineer wants to ensure that instances in a private subnet can initiate outbound connections to the internet for software updates, but the instances should not be directly reachable from the internet. Which configuration should the engineer use?
103A security engineer is configuring a VPC Service Controls perimeter to protect a Cloud Storage bucket. The perimeter includes a project that hosts a Compute Engine instance. The instance needs to access the bucket using its service account. The engineer wants to ensure that the instance's requests to the bucket do not leave the perimeter and are not blocked. What should the engineer do?
104A company has a VPC Service Controls perimeter that protects a Cloud Storage bucket. They need to allow a specific on-premises application to access the bucket using a service account, but only when the request originates from a specific corporate IP range. The on-premises application authenticates with a service account key. Which configuration should the security engineer implement?
105A security engineer is configuring firewall rules for a VPC that hosts production workloads. The team wants to reduce the attack surface by ensuring that only explicitly required traffic is allowed, and they want to verify the effective rules after changes. Which two actions should the engineer take? (Choose two.)
106A company runs a web application on Compute Engine behind an external HTTP(S) load balancer. The security team must inspect incoming traffic for known malicious source IPs and rate-limit abusive clients, while keeping the backend VMs hidden from direct internet access. Which combination should the engineer implement?
107A security engineer needs to ensure that all egress traffic from a VPC to external destinations is inspected by a third-party next-generation firewall appliance running on Compute Engine, while allowing Google API traffic to bypass the appliance. The VMs currently have external IP addresses. What should the engineer implement?
108A company needs to connect its on-premises network to a Google Cloud VPC. The security team requires that traffic be encrypted and that the connection support dynamic routing via BGP. They also want a solution that can be set up quickly without ordering a dedicated physical circuit. What should they use?
109A security engineer needs to inspect outbound traffic from a VPC for intrusion attempts and malware, and to block connections to known malicious destinations. The team wants to use a managed Google Cloud service that can be attached to the VPC and does not require deploying third-party virtual appliances. Which service should the engineer use?
110A retail company exposes an internal API on a global external Application Load Balancer. The security team must ensure that only clients presenting a valid client certificate issued by the company's internal CA can reach the backend, while still allowing unauthenticated health checks from Google's load balancer infrastructure. They configure a server TLS policy and a target HTTPS proxy. What must they also configure to enforce mutual TLS correctly?
111A company has a web application behind an external HTTP(S) load balancer. The security team wants to block traffic from a specific list of IP addresses known to be malicious. They also want to log all requests that match the rule. What should they do?
112A financial services company must log all denied connections to its production VPC, which contains hundreds of VM instances and several firewall rules. The security team needs visibility into which denied flows target which instances, without capturing every allowed flow and generating excessive log volume. What should they do?
113A security engineer needs to ensure that all traffic between two VPC networks in different projects is encrypted and authenticated. The networks are connected via VPC Network Peering. What should the engineer do?
114A media company runs a Shared VPC where the host project contains all subnets and the service projects contain the workloads. A security engineer in a service project needs to create a firewall rule that allows SSH from a bastion subnet in the host project to instances in that service project only. The engineer has the compute.securityAdmin role on the service project. What is the correct approach?
115A security engineer is configuring a VPC firewall rule to allow traffic from a specific on-premises network to a Compute Engine instance over Cloud VPN. The on-premises network uses a dynamic routing protocol, and the engineer wants to ensure that the firewall rule only allows traffic from the exact on-premises subnet. Which source should the engineer specify in the firewall rule?
116A healthcare company wants to give a partner organization access to a single internal web application hosted on Compute Engine instances in a private subnet with no external IP addresses. The partner has its own Google Cloud project and will connect from its own VPC. The security team wants the connection to stay off the public internet and to avoid exposing the application broadly. Which two configurations should they use? (Choose two.)
117A security engineer needs to allow HTTP traffic from the internet to a web server hosted on a Compute Engine instance. The instance is in a VPC network with a default deny ingress rule. The engineer wants to minimize the attack surface. What should the engineer do?
118A security engineer needs to implement hierarchical firewall policies to enforce a rule that denies all egress traffic to a specific CIDR range (203.0.113.0/24) for all projects under a folder. The rule must be inherited by all projects and cannot be overridden. Which configuration should the engineer use?
119A security engineer needs to allow SSH access to a group of Compute Engine VMs from a specific corporate IP range. The VMs are in a VPC network with a firewall rule that denies all ingress by default. Which firewall rule should the engineer create?
Be able to map a threat scenario to the right Google Cloud control: Cloud Armor WAF rules for L7 attacks, Cloud NGFW and firewall policies for L3/L4, Cloud IDS for deep packet inspection, and PSC or VPC Service Controls for private segmentation. The key is attaching each control at the correct layer.
The Courseiva PCSE question bank contains 119 questions in the Configuring Network Security domain, covering the 22% of the exam attributed to this domain in the official Google Cloud blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Configuring Network Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included