A DevOps team wants to automatically provision and renew SSL certificates for a global HTTPS load balancer. Which certificate management option should be used?
A security engineer wants to apply a baseline set of firewall rules that apply to all new and existing VMs in an organization, and these rules must not be overridden by project-level rules. Which approach should be used?
An organization uses SSL policies for their HTTPS load balancer. They need to allow TLS 1.2 and 1.3 only, and use the most secure cipher profile available. Which SSL policy configuration should they choose?
A company wants to detect and block SQL injection attacks targeting their web application hosted on Compute Engine behind a Cloud Load Balancer. Which TWO steps should they take? (Choose TWO.)
A financial services company must ensure that all data in Cloud Storage remains within a specific region and that no data can be accessed from outside the corporate network. They also need to allow a partner organization to access a specific bucket. Which THREE Google Cloud services or features should be combined to meet these requirements? (Choose THREE.)
An organization wants to restrict access to a Cloud Storage bucket so that only resources in a specific VPC network can reach it, without using public IP addresses. Which solution should they implement?
A security engineer needs to allow HTTP (port 80) traffic from all VMs in the production environment to a specific set of VMs running a web server. The web server VMs are identified by a service account 'web-sa@...'. Which firewall rule configuration should the engineer create?
A company wants to enforce that all VPC firewall rules in an organization must be centrally managed and cannot be overridden by lower-level projects. Which approach should they use?
A company wants to provide private connectivity from its VPC to Google APIs (e.g., Cloud Storage, BigQuery) without using public IPs or NAT. The solution must also support on-premises connectivity via Cloud VPN. Which service should they use?
An organization needs to restrict access to Cloud Storage buckets so that only requests from a specific range of IP addresses (e.g., corporate VPN) are allowed. They also want to block all other IPs. Which combination of services should they use?
A company wants to enable private connectivity from its on-premises network to Google APIs (e.g., Cloud Storage, BigQuery) without using public IPs. They have a Cloud VPN connection to a VPC. Which TWO services or configurations are required? (Choose two.)
A security engineer is designing a VPC Service Controls perimeter to protect sensitive BigQuery data. They need to allow a specific on-premises application (source IP range 203.0.113.0/24) to query BigQuery, and also allow a managed instance group in another project (project 'analytics') to export data from BigQuery to Cloud Storage. Which THREE configurations are required? (Choose three.)
A company uses VPC Service Controls to protect a project containing BigQuery datasets. They have an ingress rule that allows traffic from an on-premises network via a Cloud VPN tunnel. The on-premises IP range is 10.0.0.0/8. However, users on-premises are still getting access denied errors when querying BigQuery. The VPC Service Controls perimeter is in dry-run mode. What is the most likely cause?
A company uses Cloud Armor security policies to protect their HTTP load balancer. They need to block requests from a specific geographic region (country X) and also limit requests from any IP to 1000 requests per second. They also want to use preconfigured rules for SQL injection prevention. What is the correct way to combine these requirements in a single security policy?
A security engineer needs to detect and alert on network-based threats such as malware and command-and-control traffic within their Google Cloud VPC. They want a managed service that provides deep packet inspection and integrates with their existing security operations. Which service should they use?
An organization uses VPC Service Controls with a service perimeter that includes Cloud Storage and BigQuery. They need to allow a specific on-premises service account to write data to a Cloud Storage bucket inside the perimeter. The on-premises network connects via Cloud VPN. What must be configured in the perimeter?
A company needs to enforce that all incoming traffic to their HTTPS load balancer must use TLS 1.2 or higher. Which SSL policy setting should they configure on the target HTTPS proxy?
A company is implementing VPC Service Controls to protect a project that contains Cloud Storage and BigQuery. They want to allow a specific on-premises service account to read data from Cloud Storage and write to BigQuery. The on-premises network connects via Cloud VPN. Which TWO components must be configured in the service perimeter? (Choose two.)
A company is deploying a new internal application on Google Cloud. They want to ensure that VM instances in a specific subnet can only communicate with each other and with a load balancer that fronts the application. They also want to allow SSH access from a bastion host. Which TWO firewall rules should they create? (Choose two.)
An organization needs to block all inbound SSH traffic (port 22) to a set of VM instances that have a common tag 'ssh-restricted'. They want to deny this traffic at the VPC firewall level. Which firewall rule configuration should they use?
A company uses hierarchical firewall policies at the organization level to enforce a baseline deny-all rule. A project administrator wants to create a firewall rule that allows HTTP traffic to a specific VM. Which statement is correct?
A financial services company must ensure that all data egress from a VPC to BigQuery goes through a Private Service Connect endpoint for private access. They have set up the PSC endpoint and configured DNS. However, connections from VMs are still using the public internet. What is the most likely cause?
An organization wants to use Cloud IDS to detect network threats within their VPC. They have enabled the Cloud IDS endpoint and configured packet mirroring. Which of the following is required for the packet mirroring policy to work?
An organization wants to enforce that all egress traffic from a VPC to the internet must go through a Cloud NAT gateway for logging and IP management. They also need to block all other direct outbound traffic. Which THREE steps should they take? (Choose THREE.)
A security engineer wants to restrict access to Cloud Storage buckets such that only workloads running on Compute Engine VMs in a specific VPC can read data. The VMs are managed by multiple GKE clusters and autoscaling instance groups. Which approach BEST enforces this restriction?
A company is deploying an internal service on GKE that needs to be accessible privately from on-premises data centers over a VPN connection. The service should not be exposed to the internet. Which connectivity solution is MOST appropriate?
An organization has a security policy that requires TLS 1.2 or higher for all HTTPS traffic to their external HTTP(S) load balancer. They also need to disable weak cipher suites. Which configuration should be applied?
An engineer needs to allow a specific service account from another project to access a Cloud Storage bucket in the current project. The engineer wants to use the principle of least privilege. Which IAM role should be granted directly on the bucket to the service account?
A company uses VPC Service Controls to protect a service perimeter around BigQuery. They need to allow a specific on-premises application (with static IP 203.0.113.10) to query BigQuery tables within the perimeter, while still blocking other internet traffic. Which configuration should be used?
A security team needs to inspect all egress traffic from Compute Engine instances for malware using a third-party security appliance. They want to deploy the appliance in a separate VPC and route all egress traffic through it. Which THREE components are required? (Choose 3)
An organization wants to enforce that all Compute Engine instances have Confidential Computing enabled for sensitive workloads. Which TWO steps should be taken? (Choose 2)
A security engineer wants to allow egress traffic from Compute Engine instances to the internet only for updates to a specific set of packages. All other egress must be denied. Which VPC firewall rule configuration should the engineer use?
A company uses VPC Service Controls in dry-run mode to test a new service perimeter that includes BigQuery. They want to monitor any violations without actually blocking access. Where can they view the logs of these dry-run violations?
A security engineer needs to restrict access to a Cloud Storage bucket so that only a specific set of Compute Engine instances can read objects. The instances are in the same project and VPC network. The engineer wants to use VPC firewall rules for this purpose. Which two configurations are REQUIRED? (Choose two.)
A company has set up a VPC Service Controls perimeter that includes Cloud Storage. They want to allow a specific on-premises server to copy data to a Cloud Storage bucket inside the perimeter. The on-premises server uses an external IP address. Which configuration is required?
A company wants to protect a web application hosted on Google Cloud from common web attacks like SQL injection and cross-site scripting (XSS). They have deployed a global external HTTPS load balancer. Which TWO services or configurations should they use?
An organization wants to use VPC Service Controls to protect BigQuery data. They need to allow a group of data analysts to access BigQuery from outside the perimeter (e.g., from their laptops) while maintaining the perimeter for all other users. Which TWO configurations are necessary?
A company wants to deploy a web application with a global load balancer and needs to configure SSL/TLS termination. They want to use a certificate from their own CA and have the ability to manage multiple certificates for different domains. Which THREE steps should they take?
A security engineer is designing a network security architecture for a multi-project environment. They need to enforce a baseline set of firewall rules across all projects in the organization, but allow individual project teams to add their own specific rules. Which TWO components should they use?
Your organization wants to enforce that all VMs in a project can only communicate with a specific Cloud Storage bucket, and no other external IP addresses. You need to configure firewall rules to achieve this. Which approach should you take?
You are designing a VPC Service Controls perimeter to protect a project containing BigQuery datasets accessible from a data analytics VPC. You need to allow a specific set of on-premises users (identified by IP range 203.0.113.0/24) to query BigQuery from outside the perimeter, but block all other external access. What is the correct configuration?
You are designing a private connectivity solution for a Google Cloud project that needs to access Google APIs (e.g., Cloud Storage) without traversing the public internet. The VPC has on-premises connectivity via Cloud VPN. Which THREE steps are required to achieve private, on-premises to Google API access? (Choose 3)
A company uses a Shared VPC where the host project contains a subnet 'subnet-a' (10.0.1.0/24) and a service project contains instances that need to communicate with each other. A security engineer must ensure that instances in the service project can only receive traffic from other instances within the same service project, and not from instances in other service projects or the host project. What should the engineer do?
A security engineer manages a Shared VPC where the host project contains a subnet named 'app-subnet' (10.0.1.0/24). A service project has several Compute Engine instances that should only communicate with each other and with an on-premises database at 192.168.100.5. No other traffic should be allowed. The engineer creates a firewall rule with direction INGRESS, action ALLOW, targets 'app-subnet', source ranges '10.0.1.0/24,192.168.100.5', and protocol tcp:3306. Which additional action is required to enforce the desired restriction?
A company has a VPC with several subnets. They want to allow SSH access to all instances in a specific subnet from a corporate IP range, but only during business hours. What is the most efficient way to achieve this?
A security engineer is deploying a three-tier application in a single Google Cloud VPC. The web tier runs in an unmanaged instance group, the app tier in a managed instance group, and the database tier on Compute Engine. The engineer must ensure that only the app tier can initiate connections to the database tier on TCP port 5432, while the web tier can reach the app tier on TCP port 8080. The database tier must not initiate outbound connections to any internal subnet. Which configuration should the engineer use?
A security engineer needs to ensure that all egress traffic from a subnet in a Shared VPC is inspected by a third-party appliance before reaching the internet. The service project's VMs must not be able to bypass the inspection. What should the engineer configure?
A security engineer is configuring a shared VPC in Google Cloud. The host project contains the VPC network, and service projects contain the resources. The engineer needs to ensure that a firewall rule created in the host project applies to all service projects, but also needs to allow service project administrators to create their own firewall rules that only affect their own projects. What should they configure?
A security engineer is configuring a VPC Service Controls perimeter for a project containing a Cloud Storage bucket. The perimeter has an access level that allows users from the corporate network (IP 192.0.2.0/24). However, users are reporting that they cannot access the bucket from the corporate network when using the Cloud Storage API. The engineer verifies that the VPN tunnel is up and the users' IPs are within the allowed range. What is the most likely cause?
A security engineer has deployed a web application on a Compute Engine instance group behind an external HTTP(S) load balancer. The application must be reachable from the internet, but the engineer wants to ensure that only traffic from the load balancer's backend service can reach the instances. The engineer has created a firewall rule that allows ingress from the load balancer's health check ranges (130.211.0.0/22 and 35.191.0.0/16) on port 80, but the instances are still directly reachable from the internet. What should the engineer do to restrict access to only the load balancer?
A company runs a three-tier web application on Compute Engine. The web tier is in subnet web-subnet (10.0.1.0/24) and the database tier is in db-subnet (10.0.2.0/24). A security engineer must ensure that the database VMs accept TCP 3306 connections only from the web tier, and that no other VM in the VPC, including future subnets, can reach the database on that port. What should the engineer do?
A security engineer needs to restrict which Google Cloud APIs can be reached from a subnet, and also block traffic to specific external IP addresses, all from a single centralized policy that is evaluated before firewall rules. What should they configure?
A company uses Cloud VPN with dynamic routing (BGP) to connect its on-premises network to a VPC. The security team wants to ensure that only specific on-premises subnets (192.168.10.0/24 and 192.168.20.0/24) can reach resources in the VPC, and that no other routes from on-premises are accepted. They also want to prevent the VPC from advertising its subnets to on-premises. Which two actions should they take? (Choose two.)
A security engineer needs to ensure that all traffic between two projects in the same organization is encrypted and authenticated, and that only specific instances can communicate. They want to avoid managing individual firewall rules for each instance. What should they use?
A security engineer is configuring a Shared VPC in Google Cloud. The host project contains a subnet in us-central1 with secondary ranges for pods and services. A service project runs a GKE cluster that uses this subnet. The engineer must ensure that pods in the service project can communicate with each other and with the control plane, but pods must not be able to reach the internet directly. Which configuration should the engineer implement?
A security engineer is configuring firewall rules for a VPC that has both frontend and backend subnets. The frontend subnet hosts web servers, and the backend subnet hosts database servers. The engineer wants to allow only the web servers to connect to the databases on TCP port 3306, and wants the rule to apply regardless of the source IP addresses assigned to the web servers. Which approach should the engineer use?
A company runs a three-tier web application on Compute Engine. The security team wants to ensure that only the backend VMs in a specific instance group can accept connections on TCP port 8080 from the frontend VMs in another instance group, and that no other VM in the VPC can reach that port. They also need to log all denied connection attempts for auditing. What should they do?
A security engineer wants to restrict access to a Compute Engine VM so that only SSH from a specific CIDR range 203.0.113.0/24 is allowed, and all other ingress traffic is denied. What should the engineer do?
A security engineer must allow a partner organization's on-premises application to connect to a service in a Google Cloud VPC over a dedicated, private connection. The partner uses a different Autonomous System Number and manages its own edge router. The engineer wants BGP route exchange with the partner and the ability to control which Google Cloud routes are advertised. Which connectivity option should the engineer choose?
A security engineer is configuring Cloud Armor security policies for an external HTTP(S) load balancer. They need to block traffic from a specific set of IP addresses and also mitigate a recent spike in HTTP flood attacks. Which two actions should the engineer take? (Choose two.)
A company wants to give its on-premises data center private connectivity to workloads in a Google Cloud VPC without using the public internet. The security team requires that the connection support redundant BGP sessions and that traffic be encrypted in transit by the solution itself. Which two components should be used? (Choose two.)
A security engineer needs to allow a specific on-premises application to access a Cloud Run service that is protected by a VPC Service Controls perimeter. The on-premises application connects to Google Cloud via Cloud VPN. The engineer wants to grant access without exposing the service to the public internet. Which solution should the engineer implement?
A company has a VPC with two subnets: subnet-a (10.0.1.0/24) in us-central1 and subnet-b (10.0.2.0/24) in europe-west1. They have a firewall rule that allows ingress from 10.0.1.0/24 to all instances in the VPC. A security engineer needs to ensure that instances in subnet-b can only receive traffic from subnet-a on TCP port 22, and all other traffic is denied. What should the engineer do?
A security engineer is configuring Cloud Armor security policies for an external HTTP(S) load balancer. They want to mitigate application-layer DDoS attacks and block traffic from specific countries. Which two actions should they take? (Choose two.)
A company has a VPC with two subnets: subnet-a (10.0.1.0/24) and subnet-b (10.0.2.0/24). A security engineer needs to allow HTTP traffic from any VM in subnet-a to any VM in subnet-b, but deny all other traffic between the subnets. Which firewall rule should be created?
A security engineer is configuring VPC Service Controls to protect a Cloud Storage bucket and a BigQuery dataset. The engineer needs to allow a specific set of on-premises servers to access these services through a VPN connection, while ensuring that the data cannot be exfiltrated to unauthorized projects. The on-premises servers use a dedicated IP range. Which two configurations should the engineer implement? (Choose two.)
A security engineer needs to allow outbound traffic from a VM instance to a specific external IP address on TCP port 443, while denying all other outbound traffic. The VM has an external IP address. The engineer wants to implement this using VPC firewall rules and ensure that the rules are evaluated correctly. What should the engineer do?
A security engineer is configuring Cloud Armor security policies for an external Application Load Balancer. The security team wants to block traffic from specific countries, allow known partner IP addresses regardless of other rules, and protect against volumetric attacks. (Choose two.)
A security engineer is configuring a VPC Service Controls perimeter to protect sensitive data in Cloud Storage and BigQuery. They need to allow access from a specific on-premises network while ensuring that data cannot be exfiltrated to unauthorized projects. Which two configurations should they implement? (Choose two.)
Your organization runs a three-tier application across two VPC networks, web-vpc (10.0.0.0/24) and app-vpc (10.1.0.0/24), connected by VPC Network Peering. The application team reports that the web tier in web-vpc cannot open a TCP connection to the app tier on port 8443, even though a firewall rule named allow-8443 exists in app-vpc with source range 10.0.0.0/24 and target tag app-server. You verify the app-tier VMs carry the app-server network tag and are listening on 8443. What should you check first?
A security engineer needs to allow HTTP and HTTPS traffic from the internet to a set of web servers running on Compute Engine instances. The instances are in a subnet with no external IP addresses, and they are behind an external HTTP(S) load balancer. Which firewall rule should the engineer create?
A security engineer is setting up Cloud NAT for a VPC to allow instances without external IP addresses to access the internet. The engineer must ensure that the NAT gateway logs all connections and that the logs are exported to Cloud Logging for auditing. (Choose two.)
A security engineer is configuring Cloud Armor security policies for an external HTTP(S) load balancer. The engineer needs to protect the backend service from common OWASP Top 10 attacks such as SQL injection and cross-site scripting, and also wants to rate-limit requests from specific IP addresses to mitigate brute-force attacks. Which two actions should the engineer take? (Choose two.)
A security engineer is configuring Cloud NAT for a VPC network to allow instances without external IP addresses to access the internet. The engineer needs to ensure that the NAT configuration meets security best practices and operational requirements. Which two actions should the engineer take? (Choose two.)
A security engineer is configuring a Private Service Connect (PSC) endpoint to access a published service in another VPC. The service is exposed via an internal TCP proxy load balancer. The engineer needs to ensure that only specific consumer VMs can access the service, and that traffic does not leave the Google Cloud network. What should the engineer do?
A security engineer is configuring Cloud NAT for a VPC to allow instances without external IP addresses to access the internet. The engineer must ensure that only specific instances can use Cloud NAT, and that the NAT IP addresses are static and reserved. Which two configurations should the engineer implement? (Choose two.)
A security engineer is setting up a Shared VPC in Google Cloud. The host project contains the shared VPC network, and several service projects contain resources that need to communicate with each other. The engineer needs to ensure that only specific service projects can use certain subnets in the shared VPC. What should the engineer do?
A security engineer needs to provide outbound internet access to a private Compute Engine VM that has no external IP address. The VM must initiate connections to external web services, but the VPC must not have a default route to the internet gateway. Which configuration should the engineer implement?
A company uses a Shared VPC where the host project contains a subnet with secondary IP ranges for GKE pods and services. A security engineer needs to create a firewall rule that allows ingress to the GKE pods from a specific on-premises CIDR range. The rule must apply only to the GKE pods and not to other VMs in the same subnet. What should the engineer do?
A security engineer is configuring Cloud IDS to monitor traffic for a VPC network. They need to ensure that Cloud IDS can inspect traffic between on-premises and Google Cloud, as well as between VMs within the same VPC. Which two configurations are required to achieve this? (Choose two.)
A security engineer needs to restrict access to Cloud Storage buckets so that only resources in a specific VPC can reach the Google APIs. Which Google Cloud service should be used?
An organization wants to enforce a security policy that denies all egress traffic to the internet from all projects in the organization, except for traffic from a specific set of VMs tagged with 'allow-egress'. Which approach should be used?
A company uses VPC Service Controls to protect a BigQuery dataset. They need to allow an external on-premises application to query the dataset without being inside the service perimeter. The external application has a static IP address. Which configuration is required?
A company wants internal VMs to access Google APIs (e.g., Cloud Storage, BigQuery) without traversing the internet. What is the simplest configuration?
An organization uses VPC Service Controls in dry-run mode for a project containing Google Cloud Storage. They notice that BigQuery jobs are being logged as violations. How should they interpret this?
A service provider wants to expose an internal service to external consumers in a controlled manner, without giving them direct access to the VPC. Which Google Cloud service should be used?
An organization wants to implement a zero-trust network security model for their Google Cloud environment. Which TWO practices should they adopt? (Choose TWO.)
An organization uses VPC Service Controls to protect BigQuery datasets. They need to allow a specific on-premises application, which uses a static IP address, to query a BigQuery dataset inside the service perimeter. Which configuration is required?
A web application behind an HTTPS load balancer is experiencing a high volume of malicious requests with SQL injection patterns. The security team wants to block these requests with minimal latency impact. Which Cloud Armor feature should they use?
An organization uses a global HTTPS load balancer with a Google-managed SSL certificate. The certificate was automatically provisioned and renewed. Recently, the certificate renewal failed and the site shows a warning. The load balancer's frontend uses the certificate. What is the most likely cause?
A security engineer needs to monitor network traffic for potential threats in a VPC. They want to inspect all traffic for malware signatures and alert on high-severity threats. The solution should be natively integrated with GCP. Which service should they use?
A company wants to enforce that traffic between two projects in the same organization must go through a central inspection VPC. They need a firewall rule that denies all traffic between the projects except through the inspection VPC. Which type of firewall rule should they use?
A company has a global HTTPS load balancer and wants to use a self-managed SSL certificate. They have uploaded the PEM-encoded certificate and private key to the load balancer. However, the certificate is about to expire. What is the correct way to renew it without downtime?
A security team wants to block all incoming traffic from a specific country to their web application behind a global HTTPS load balancer. They also need to allow traffic from all other countries. Which Cloud Armor feature should be used?
A security team wants to enforce SSL/TLS best practices for their HTTPS load balancer. They need to require TLS 1.2 or higher and restrict ciphers to strong ones only. Which TWO actions should they take? (Choose two.)
An organization wants to restrict access to Google Cloud APIs such as BigQuery and Cloud Storage so that only requests originating from a specific VPC network are allowed. Which Google Cloud service should they use?
A security team needs to apply a set of firewall rules that enforce baseline security for all VPC networks across multiple projects in an organization. These rules must be inherited and cannot be overridden by project-level rules. What should they use?
An engineer wants to allow egress traffic from a group of VM instances with a specific service account to a set of IP addresses. They need to choose between using tags or service accounts as targets in a VPC firewall rule. Which approach is recommended for better security and why?
An organization wants to provide private, on-premises access to Google Cloud APIs (e.g., Cloud Storage, BigQuery) without traversing the public internet. They have a Direct Connect link to Google Cloud. Which solution should they implement?
A company wants to automatically provision and renew SSL certificates for their HTTPS load balancer. They want Google to manage the certificate lifecycle. Which certificate type should they use?
A company is using Cloud Armor with adaptive protection enabled. They notice that adaptive protection has generated a rule that is blocking some legitimate traffic. What should they do to minimize false positives while still benefiting from adaptive protection?
An organization has multiple VPC networks in different projects. They need to centrally manage firewall rules that apply to all VPCs in the organization and ensure that project owners cannot override them. Which solution should they use?
A security team is configuring Cloud Armor to protect a web application. They need to block requests that contain SQL injection patterns, block requests from a known malicious IP list, and limit requests from any single IP to 2000 requests per minute. Which THREE actions must they take? (Choose three.)
A security engineer wants to restrict access to a Cloud Storage bucket so that only requests originating from within a specific VPC network can access the bucket. Which Google Cloud service should they use?
A company wants to use Cloud Armor Managed Protection Plus to protect their HTTP(S) load balancer from DDoS attacks. They need to automatically block traffic from IP addresses that exhibit anomalous behavior based on machine learning. Which Cloud Armor feature should they enable?
An engineer needs to ensure that only VMs with a specific service account (sa-prod@project.iam.gserviceaccount.com) can access a Cloud Spanner instance. They want to control this at the network level, not using IAM. Which VPC firewall rule configuration should they use?
A company wants to automatically provision and renew SSL certificates for their HTTPS load balancer. They do not want to manually manage certificate files. Which approach should they use?
A security team needs to apply a security policy that blocks requests to their HTTP load balancer from a specific geographic region (e.g., Country A). Which Cloud Armor feature should they use?
An organization uses VPC Service Controls to protect BigQuery. They want to test a new access level that allows access only from a specific IP range before enforcing it. Which mode should they use?
A company has multiple VPCs in different projects that need to privately connect to a common internal service (e.g., a managed database) running in a central project. They want to expose this service via Private Service Connect. Which type of PSC endpoint should the consumer VPCs create?
A DevOps engineer wants to use Cloud Armor to block common web application attacks like SQL injection and cross-site scripting. Which feature should they enable?
A security engineer is configuring a VPC Service Controls perimeter to protect a Cloud Storage bucket. They want to allow a specific on-premises network (IP range 203.0.113.0/24) to access the bucket, while still blocking other external networks. Which TWO components must they configure? (Choose TWO.)
A company wants to use Cloud IDS to detect threats in their VPC. They have created a Cloud IDS endpoint and need to configure packet mirroring. Which TWO resources must be in place for packet mirroring to work? (Choose TWO.)
An organization wants to enforce that all Compute Engine instances in a project have a specific tag (e.g., 'env=prod') before they can be created. Which approach should be used?
An organization wants to allow only specific trusted IP ranges to access a web application behind a Cloud Load Balancer. Which Cloud Armor feature should be used?
A company wants to enforce that no Compute Engine firewall rule in any project under an organization can have a source range of 0.0.0.0/0 for RDP (port 3389). Which approach should be used?
An engineer needs to allow HTTP traffic from instances tagged 'web-server' to instances tagged 'app-server' on port 8080 within the same VPC. Which firewall rule should be created?
An organization uses Certificate Manager to provision SSL certificates for multiple domains across several load balancers. They want to automate certificate renewal. Which type of certificate should be used?
A company wants to prevent data exfiltration by restricting access to Google APIs from only authorized VPC networks. They also need to allow a specific on-premises IP range to access BigQuery. Which TWO services should be used together? (Choose 2)
A company wants to restrict access to Cloud Storage buckets so that only resources in a specific VPC network can reach them, and data cannot be exfiltrated to other networks. Which Google Cloud service should they use?
An organization has a hub-and-spoke VPC setup with Shared VPC. The security team wants to enforce a rule that all egress traffic from any project in the organization must pass through a central inspection appliance in the hub VPC. Which firewall configuration approach meets this requirement?
A company wants to expose an internal web service running on a private GKE cluster to other services within the same VPC network using a private IP address. They do not want to use a public load balancer. Which Google Cloud service should they use?
A security engineer needs to block traffic from all IP addresses in a specific geographic region from reaching an HTTPS load-balanced application. The application uses Cloud Load Balancing with an external HTTPS load balancer. Which approach should the engineer use?
A company uses Cloud Armor Managed Protection Plus to protect their applications. They want to automatically block IP addresses that are identified as malicious by adaptive protection. How should they configure this?
An organization needs to enforce a TLS minimum version of 1.2 for all traffic to their HTTPS load balancers. They have multiple load balancers serving different domains. Which Google Cloud feature should they use?
A security team wants to detect and block network-based threats such as malware and command-and-control traffic within their VPC. They need a managed service that provides deep packet inspection. Which Google Cloud service should they use?
A company has a VPC Service Controls perimeter that includes BigQuery and Cloud Storage. They need to allow a specific on-premises application (with a static IP) to access a BigQuery dataset within the perimeter. Which configuration should they use?
A company uses Cloud Armor to protect a web application. They want to block requests that contain SQL injection patterns based on the OWASP ModSecurity Core Rule Set. Which preconfigured rule set should they enable?
A company is designing a secure multi-tenant environment in Google Cloud. Each tenant has its own VPC network and resources. The security team wants to centrally enforce a rule that denies all egress traffic to the internet from tenant VPCs, except for traffic to specific trusted IP ranges for software updates. They also want to ensure that tenant admins cannot override this rule. Which two actions should they take? (Choose two.)
A company is deploying a web application behind an external HTTPS load balancer. They want to protect against common web attacks such as XSS, SQLi, and LFI using preconfigured rules. They also need to allowlist specific IP addresses that belong to partners. Which three Cloud Armor features should they use? (Choose three.)
An organization wants to restrict access to Google Cloud APIs such as BigQuery and Cloud Storage so that only resources within a specific VPC network can call these APIs, and no traffic from other VPCs or on-premises networks is allowed. Which Google Cloud service should they use?
A security engineer needs to configure firewall rules to allow traffic from a set of compute instances to a set of backend instances. The engineer wants to use a method that is more secure and scalable than using network tags. Which approach should they use?
A company wants to allow users from a specific on-premises IP range to access a service deployed on Google Cloud, but only if the user's device is compliant with corporate security policies (e.g., has antivirus enabled). Which combination of services can achieve this?
A company wants to use a Google Cloud load balancer with an SSL certificate that is automatically provisioned and renewed. Which type of certificate should they use?
A security engineer needs to block traffic to a set of VMs from specific IP addresses and also apply rate limiting for HTTP traffic. The VMs are behind a global external HTTPS load balancer. Which service should they use?
A company wants to provide private connectivity from its on-premises network to Google Cloud APIs (e.g., BigQuery, Cloud Storage) without traversing the public internet. They have an existing Dedicated Interconnect connection. Which solution should they use?
An organization has a hierarchical firewall policy at the organization level that denies all ingress traffic from the internet. A project team needs to allow HTTP traffic from the internet to a specific VM. How should they achieve this?
A company wants to detect and alert on potential network threats, such as malware and command-and-control traffic, within their VPC. They need a managed service that integrates with packet mirroring. Which Google Cloud service should they use?
A company's security policy requires that all traffic to a Google Cloud load balancer use TLS 1.2 or higher and only accept strong ciphers. They want to enforce this using a Google Cloud resource. Which resource should they configure?
A company wants to use Private Service Connect to publish a managed service (e.g., a custom application) so that consumers can access it privately within Google Cloud. Which THREE resources are involved in this setup?
Your organization uses Cloud Armor to protect HTTP Load Balancers. You need to block all incoming requests from a specific geographic region (country code 'XY') while allowing all other traffic. What is the correct configuration?
You manage a Google Cloud environment using shared VPC with multiple service projects. You need to enforce consistent firewall rules across all projects in the organization, ensuring that certain security rules cannot be overridden by project administrators. Which TWO steps should you take? (Choose 2)
A company's security team wants to inspect all egress traffic from their Google Cloud VPC to the internet for malware and data exfiltration. They need to ensure that traffic from a specific subnet is first inspected by a third-party firewall appliance deployed on a Compute Engine instance before it reaches the internet. The solution must be centrally managed and support high availability. What should they configure?
A security engineer is configuring a Shared VPC in Google Cloud. The host project contains a subnet named 'prod-subnet' (10.0.1.0/24) in us-central1. A service project has a Compute Engine instance that must communicate with an on-premises database at 192.168.100.0/24 over a Cloud VPN tunnel. The engineer needs to ensure that return traffic from the on-premises database is routed back to the service project instance. What should the engineer do?
A security engineer is configuring a VPC Service Controls perimeter to protect a sensitive BigQuery dataset. They need to allow a specific on-premises application to access the dataset using a VPN connection. The on-premises application uses a service account to authenticate. What should they do to allow this access while keeping the perimeter secure?
A security engineer needs to allow SSH access to a Compute Engine instance from a specific on-premises IP range (203.0.113.0/24) only when the user's device is compliant with corporate policy. The company uses BeyondCorp Enterprise and has an Identity-Aware Proxy (IAP) setup. The engineer wants to enforce device compliance without exposing the instance to the internet. What should the engineer do?
A security team needs to inspect outbound traffic from a VPC to detect and block malicious domains before it leaves the Google Cloud network. They want to enforce the policy centrally and avoid managing individual instance firewalls. Which Google Cloud service should they use?
A company is deploying a web application on Compute Engine instances behind an external HTTP(S) load balancer. They want to protect the application from common web attacks such as SQL injection and cross-site scripting, and also mitigate denial-of-service attacks. They need to implement a solution that allows granular control based on request attributes. Which two Google Cloud services should they use? (Choose two.)
A company is deploying a VPC Service Controls perimeter to protect sensitive data in BigQuery and Cloud Storage. They need to allow a specific on-premises application to access these services through a Cloud VPN tunnel. The application runs on a server with IP 198.51.100.10. Which two configurations are required to permit this access while maintaining the perimeter? (Choose two.)
A security engineer needs to ensure that all traffic between two subnets in the same VPC network is logged for auditing purposes. They want to capture details such as source and destination IP addresses, ports, and protocol. What should they enable?
A security engineer needs to ensure that all outbound traffic from a Compute Engine instance to the internet goes through a specific set of IP addresses for auditing. The instance is in a subnet with no external IP addresses. What should the engineer configure?
A security engineer must ensure that only the production service account can access a Compute Engine VM's SSH port (22) from a specific subnet, while all other traffic is blocked. The VM's VPC has several subnets and firewall rules. Which approach should the engineer use to meet this requirement with least privilege?
A security engineer manages a Shared VPC in Google Cloud. A team in a service project runs a three-tier web application on Compute Engine. The security team requires that instances in the web tier can receive HTTP/HTTPS traffic from the internet, but the database tier must only accept connections from the web tier on TCP port 5432. All instances are in the same Shared VPC network, and each tier is identified by a network tag. Which configuration should the engineer implement to meet these requirements?
A company uses Shared VPC. The host project contains a subnet in us-central1. A service project has a VM that needs to reach an on-premises database via Cloud VPN. The security engineer must ensure that the VM's traffic to the on-premises CIDR is allowed and that return traffic is permitted. Which firewall rule should be created in the host project?
A company uses Cloud VPN to connect its on-premises network to a Google Cloud VPC. The security team wants to ensure that all traffic from on-premises to Google Cloud is encrypted and that the on-premises router can dynamically learn routes from the VPC. They also want to minimize configuration overhead. Which Cloud VPN configuration should they use?
A security engineer must allow SSH access to a set of Compute Engine VMs from a fixed set of corporate office public IP addresses. The VMs have no external IP addresses and are in a single VPC network. The engineer wants a reusable, centrally managed rule that is applied to all current and future VMs in the network. What should the engineer do?
A security engineer is deploying a three-tier web application in a single Google Cloud VPC. The database tier must accept connections only from the application tier on TCP port 5432, and the application tier must accept HTTPS traffic only from the web tier. No other internal traffic should reach these tiers. The engineer wants the rules to remain effective even if new VM instances are added to each tier. What should the engineer do?
A company uses Shared VPC. The host project contains a subnet with secondary IP ranges for GKE pods and services. A security engineer must ensure that pods in the service project can only reach a specific on-premises CIDR through a Cloud VPN tunnel, and that all other egress is blocked. What should they do?
A security engineer is configuring a Shared VPC in Google Cloud. The host project contains a subnet named 'prod-subnet' in us-central1 with secondary ranges for GKE pods and services. A service project needs to deploy a GKE cluster that uses this subnet. The engineer must ensure that the GKE cluster's pods can communicate with each other and with services, but no other service project should be able to use this subnet. What should the engineer do?
A company runs a Shared VPC host project with several service projects. Security requires that all egress traffic from service project workloads to external IP addresses be inspected by a centralized third-party appliance before leaving the VPC. The appliance is deployed in the host project and must see traffic from all service projects. Which approach should the security engineer use?
A security engineer is configuring Identity-Aware Proxy (IAP) to protect an internal web application running on a Compute Engine instance group. The application should only be accessible to users in the 'security-team@example.com' Google Group, and only from company-managed devices. The engineer has already set up the IAP-secured resource and granted the group the 'IAP-secured Web App User' role. What additional configuration is required to enforce the device policy?
A security engineer is configuring a Shared VPC in Google Cloud. The host project contains a VPC network with subnets, and several service projects are attached. The engineer needs to allow a specific service project's resources to communicate with on-premises systems over a Cloud VPN tunnel that terminates in the host project. The engineer has already created the VPN tunnel and added the on-premises routes to the host project's VPC. However, resources in the service project cannot reach the on-premises network. What is the most likely cause?
A security engineer must ensure that all egress traffic from a Compute Engine instance is inspected by a third-party firewall appliance before reaching the internet, and that the instance cannot bypass the appliance. The instance and appliance are in the same VPC. What should they configure?
A company has a VPC Service Controls perimeter that includes Cloud Storage and BigQuery. They need to allow a specific on-premises application to access these services using a dedicated Interconnect connection. The on-premises application uses a service account. What should they configure to allow access while maintaining the perimeter?
A security engineer is configuring Cloud VPN to connect an on-premises network to a Google Cloud VPC. The on-premises VPN gateway supports only IKEv2 and requires a route-based VPN. The engineer must ensure that traffic from on-premises can reach specific VM instances in the VPC, and that the VPN tunnel is highly available. Which configuration should the engineer use?
A company needs to allow its on-premises data center to reach internal Compute Engine instances over a private connection. They have set up Cloud Interconnect and want to ensure that traffic from the on-premises CIDR 10.10.0.0/16 can reach VMs in a subnet 10.0.1.0/24 on TCP port 443, but no other on-premises traffic should be allowed. They also want to avoid exposing the VMs to the internet. What should they do?
A company has a Shared VPC setup where the host project contains a VPC network, and service projects contain VM instances. A security engineer needs to create a firewall rule in the host project that allows SSH access from a specific CIDR range to all VM instances in the service projects. The engineer wants to ensure that the rule applies only to instances with a specific network tag. What should the engineer do?
A security engineer needs to allow outbound SSH (TCP port 22) from a subnet's Compute Engine instances to a specific external IP range, while denying all other outbound internet traffic. The VPC has a default route to the default internet gateway. Which firewall rule configuration should the engineer use?
A security engineer needs to provide a group of contractors with access to a web application running on a private Compute Engine instance. The contractors connect from various locations on the internet, and the company does not want to expose the application's private IP address or manage a VPN for them. The application uses HTTPS on port 443. What should the engineer implement?
A company has a VPC with two subnets in different regions. They want to ensure that a specific set of Compute Engine instances can only send traffic to the internet through a Cloud NAT gateway, and that no instance can receive unsolicited inbound traffic from the internet. They have already configured Cloud NAT on a Cloud Router in the region of the instances. Which additional configuration is needed to prevent unsolicited inbound traffic?
A company wants to protect its external HTTP(S) load balancer from volumetric DDoS attacks and application-layer attacks. They need to use Google Cloud's advanced DDoS protection and WAF capabilities. Which service should they enable?
A company wants to control which Google Cloud services its employees can access from corporate-managed devices on the corporate network. The security team wants to enforce that only approved services are reachable, and they want the policy to apply to all users on the network without installing software on each device. Which Google Cloud feature should they use?
A security engineer needs to allow SSH access to a Compute Engine VM running in a VPC, but only from a specific bastion host in the same VPC. The bastion host has IP address 10.0.1.5. The VM is in subnet 10.0.2.0/24. The engineer wants to minimize the attack surface and ensure that only the bastion can initiate SSH connections to the VM. Which firewall rule should the engineer create?
A security engineer is configuring Cloud Armor security policies for an external HTTP(S) load balancer. They need to protect against application-layer attacks and also ensure that only requests from specific countries are allowed. (Choose two.)
A security engineer is designing a Shared VPC where a central host project provides subnets to multiple service projects. The requirement is that each service project's VMs can reach only the resources in their own project, and no service project may open firewall rules that affect the host project's network. What should the engineer configure?
A company uses a Shared VPC where the host project contains subnets shared with multiple service projects. A security engineer must ensure that a specific service project's VM instances can only initiate connections to on-premises resources over Cloud VPN, and cannot reach other service projects' VMs. Which configuration should the engineer implement?
A security engineer is setting up a VPC network in Google Cloud. The engineer wants to ensure that instances in a private subnet can initiate outbound connections to the internet for software updates, but the instances should not be directly reachable from the internet. Which configuration should the engineer use?
A security engineer is configuring a VPC Service Controls perimeter to protect a Cloud Storage bucket. The perimeter includes a project that hosts a Compute Engine instance. The instance needs to access the bucket using its service account. The engineer wants to ensure that the instance's requests to the bucket do not leave the perimeter and are not blocked. What should the engineer do?
A company has a VPC Service Controls perimeter that protects a Cloud Storage bucket. They need to allow a specific on-premises application to access the bucket using a service account, but only when the request originates from a specific corporate IP range. The on-premises application authenticates with a service account key. Which configuration should the security engineer implement?
A security engineer is configuring firewall rules for a VPC that hosts production workloads. The team wants to reduce the attack surface by ensuring that only explicitly required traffic is allowed, and they want to verify the effective rules after changes. Which two actions should the engineer take? (Choose two.)
A company runs a web application on Compute Engine behind an external HTTP(S) load balancer. The security team must inspect incoming traffic for known malicious source IPs and rate-limit abusive clients, while keeping the backend VMs hidden from direct internet access. Which combination should the engineer implement?
A security engineer needs to ensure that all egress traffic from a VPC to external destinations is inspected by a third-party next-generation firewall appliance running on Compute Engine, while allowing Google API traffic to bypass the appliance. The VMs currently have external IP addresses. What should the engineer implement?
A company needs to connect its on-premises network to a Google Cloud VPC. The security team requires that traffic be encrypted and that the connection support dynamic routing via BGP. They also want a solution that can be set up quickly without ordering a dedicated physical circuit. What should they use?
A security engineer needs to inspect outbound traffic from a VPC for intrusion attempts and malware, and to block connections to known malicious destinations. The team wants to use a managed Google Cloud service that can be attached to the VPC and does not require deploying third-party virtual appliances. Which service should the engineer use?
A retail company exposes an internal API on a global external Application Load Balancer. The security team must ensure that only clients presenting a valid client certificate issued by the company's internal CA can reach the backend, while still allowing unauthenticated health checks from Google's load balancer infrastructure. They configure a server TLS policy and a target HTTPS proxy. What must they also configure to enforce mutual TLS correctly?
A company has a web application behind an external HTTP(S) load balancer. The security team wants to block traffic from a specific list of IP addresses known to be malicious. They also want to log all requests that match the rule. What should they do?
A financial services company must log all denied connections to its production VPC, which contains hundreds of VM instances and several firewall rules. The security team needs visibility into which denied flows target which instances, without capturing every allowed flow and generating excessive log volume. What should they do?
A security engineer needs to ensure that all traffic between two VPC networks in different projects is encrypted and authenticated. The networks are connected via VPC Network Peering. What should the engineer do?
A media company runs a Shared VPC where the host project contains all subnets and the service projects contain the workloads. A security engineer in a service project needs to create a firewall rule that allows SSH from a bastion subnet in the host project to instances in that service project only. The engineer has the compute.securityAdmin role on the service project. What is the correct approach?
A security engineer is configuring a VPC firewall rule to allow traffic from a specific on-premises network to a Compute Engine instance over Cloud VPN. The on-premises network uses a dynamic routing protocol, and the engineer wants to ensure that the firewall rule only allows traffic from the exact on-premises subnet. Which source should the engineer specify in the firewall rule?
A healthcare company wants to give a partner organization access to a single internal web application hosted on Compute Engine instances in a private subnet with no external IP addresses. The partner has its own Google Cloud project and will connect from its own VPC. The security team wants the connection to stay off the public internet and to avoid exposing the application broadly. Which two configurations should they use? (Choose two.)
A security engineer needs to allow HTTP traffic from the internet to a web server hosted on a Compute Engine instance. The instance is in a VPC network with a default deny ingress rule. The engineer wants to minimize the attack surface. What should the engineer do?
A security engineer needs to implement hierarchical firewall policies to enforce a rule that denies all egress traffic to a specific CIDR range (203.0.113.0/24) for all projects under a folder. The rule must be inherited by all projects and cannot be overridden. Which configuration should the engineer use?
A security engineer needs to allow SSH access to a group of Compute Engine VMs from a specific corporate IP range. The VMs are in a VPC network with a firewall rule that denies all ingress by default. Which firewall rule should the engineer create?