Courseiva
easyMultiple Choice

Google ACE Practice Question: A small business has a single Google Cloud…

A small business has a single Google Cloud project with a few Compute Engine instances running a web application. The instances are all in the same VPC and subnet. The security team wants to ensure that only HTTP (port 80) and HTTPS (port 443) traffic from the public internet is allowed to the instances, and that all other inbound traffic is blocked. They have already configured Cloud Armor for the load balancer. However, they notice that SSH traffic (port 22) is still reaching the instances from the internet, even though they do not have any explicit firewall rules allowing SSH. The project was just created and uses the default VPC network. What should they do to resolve this?

⚠ Common exam trap

ACE often tests the misconception that no explicit allow rule means no traffic, forgetting that default VPC networks include permissive default firewall rules like default-allow-ssh.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable or delete the default-allow-ssh firewall rule in the VPC.

The default VPC network in Google Cloud includes a default-allow-ssh firewall rule that permits SSH (port 22) from 0.0.0.0/0. To block SSH from the internet, they must disable or delete this rule. This is the direct cause of SSH traffic reaching the instances despite no explicit allow rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a VPC firewall rule with priority 1000 to deny ingress on port 22 from 0.0.0.0/0.

    Why it's wrong here

    Creating a VPC firewall rule with priority 1000 to deny ingress on port 22 from 0.0.0.0/0 would technically work because priority 1000 is higher than the default rule's priority of 65534, so the deny rule would take precedence. However, the simplest and most standard practice is to remove the unnecessary allow rule as in option D.

  • ✗

    Configure a route to drop traffic destined to the instances on port 22.

    Why it's wrong here

    VPC routes direct traffic by destination prefix, not by TCP port, so a route cannot drop port 22. Routes are tempting because they steer subnet and peering traffic, but port-level filtering belongs to firewall rules. The default VPC's default-allow-ssh ingress rule must be removed.

  • ✗

    Remove the SSH public key from the instance metadata.

    Why it's wrong here

    Removing the SSH key from instance metadata does not close port 22; the default VPC's default-allow-ssh ingress rule still permits the traffic. The offending firewall rule must be deleted or overridden. Key removal is tempting because it appears to revoke access, and it would be correct when the requirement is preventing a specific key holder from authenticating.

  • ✓

    Disable or delete the default-allow-ssh firewall rule in the VPC.

    Why this is correct

    The default VPC network ships with the `default-allow-ssh` ingress rule, which permits TCP port 22 from 0.0.0.0/0 and overrides the absence of custom rules. Deleting it removes the only path allowing SSH, satisfying the requirement that inbound traffic be limited to ports 80 and 443.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.