Google ACE Configuring Access and Security Practice Question
An engineer needs to allow HTTP traffic from the internet to a set of Compute Engine instances that have the network tag 'web-server'. The instances are in a VPC with a default firewall rule that denies all ingress. Which command creates the required firewall rule?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
gcloud compute firewall-rules create allow-http --allow tcp:80 --source-ranges 0.0.0.0/0 --target-tags web-server
The rule must allow TCP port 80 from source 0.0.0.0/0 to instances with target tag 'web-server'. The correct command uses '--allow tcp:80', '--source-ranges 0.0.0.0/0', and '--target-tags web-server'. Priority can be default (1000).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
gcloud compute firewall-rules create allow-http --allow tcp:80 --source-tags web-server
Why it's wrong here
The --source-tags flag restricts the rule to traffic originating from VM instances that carry the network tag 'web-server', which does not describe internet traffic. Since the requirement is to allow HTTP from the internet, the source must be specified as an IP CIDR range using --source-ranges 0.0.0.0/0. Additionally, 'web-server' should be used as a --target-tag to identify the destination VMs, not as a source filter.
- ✗
gcloud compute firewall-rules create allow-http --allow tcp:80 --source-ranges web-server
Why it's wrong here
--source-ranges expects a comma-separated list of CIDR IP address ranges (e.g., '0.0.0.0/0' or '10.0.0.0/24'), not a VM network tag or a string like 'web-server'. Passing 'web-server' as the value will cause the gcloud command to be invalid or misinterpreted, and it certainly will not allow internet traffic. For this use case, the correct source is --source-ranges 0.0.0.0/0, while --target-tags web-server selects the destination VMs.
- ✗
gcloud compute firewall-rules create allow-http --allow http --target-tags web-server
Why it's wrong here
The --allow flag requires protocol:port syntax, such as 'tcp:80' or 'udp:53', and the literal string 'http' is not a recognized protocol name in GCP firewall rules, so this rule would be rejected. Even if it were accepted, the command omits --source-ranges, meaning the rule may not match the intended internet source or could be overly broad. To permit HTTP, you must specify --allow tcp:80 and --source-ranges 0.0.0.0/0.
- ✓
gcloud compute firewall-rules create allow-http --allow tcp:80 --source-ranges 0.0.0.0/0 --target-tags web-server
Why this is correct
This command correctly opens inbound TCP port 80 to traffic from any IPv4 address (0.0.0.0/0) and applies the rule only to VM instances tagged with 'web-server', matching the requirement precisely. The combination of --source-ranges 0.0.0.0/0 for internet sources and --target-tags web-server to scope the rule to the intended backend VMs is the standard way to allow HTTP in GCP. No other flags are needed, and the protocol:port syntax 'tcp:80' is accurately specified.
Go deeper
Related to this question
Learn chapter
Compute Engine Machine Types and Families
Key term
Compute Engine
Compute Engine is Google Cloud's Infrastructure-as-a-Service (IaaS) offering that lets you create and run virtual machines on Google's infrastructure.
Key term
TCP
TCP (Transmission Control Protocol) is a core internet protocol that ensures data is sent reliably and in order between devices over a network.
About these practice questions
One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.