Courseiva

Google ACE Configuring Access and Security Practice Question

An engineer needs to allow HTTP traffic from the internet to a set of Compute Engine instances that have the network tag 'web-server'. The instances are in a VPC with a default firewall rule that denies all ingress. Which command creates the required firewall rule?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

gcloud compute firewall-rules create allow-http --allow tcp:80 --source-ranges 0.0.0.0/0 --target-tags web-server

The rule must allow TCP port 80 from source 0.0.0.0/0 to instances with target tag 'web-server'. The correct command uses '--allow tcp:80', '--source-ranges 0.0.0.0/0', and '--target-tags web-server'. Priority can be default (1000).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    gcloud compute firewall-rules create allow-http --allow tcp:80 --source-tags web-server

    Why it's wrong here

    The --source-tags flag restricts the rule to traffic originating from VM instances that carry the network tag 'web-server', which does not describe internet traffic. Since the requirement is to allow HTTP from the internet, the source must be specified as an IP CIDR range using --source-ranges 0.0.0.0/0. Additionally, 'web-server' should be used as a --target-tag to identify the destination VMs, not as a source filter.

  • ✗

    gcloud compute firewall-rules create allow-http --allow tcp:80 --source-ranges web-server

    Why it's wrong here

    --source-ranges expects a comma-separated list of CIDR IP address ranges (e.g., '0.0.0.0/0' or '10.0.0.0/24'), not a VM network tag or a string like 'web-server'. Passing 'web-server' as the value will cause the gcloud command to be invalid or misinterpreted, and it certainly will not allow internet traffic. For this use case, the correct source is --source-ranges 0.0.0.0/0, while --target-tags web-server selects the destination VMs.

  • ✗

    gcloud compute firewall-rules create allow-http --allow http --target-tags web-server

    Why it's wrong here

    The --allow flag requires protocol:port syntax, such as 'tcp:80' or 'udp:53', and the literal string 'http' is not a recognized protocol name in GCP firewall rules, so this rule would be rejected. Even if it were accepted, the command omits --source-ranges, meaning the rule may not match the intended internet source or could be overly broad. To permit HTTP, you must specify --allow tcp:80 and --source-ranges 0.0.0.0/0.

  • ✓

    gcloud compute firewall-rules create allow-http --allow tcp:80 --source-ranges 0.0.0.0/0 --target-tags web-server

    Why this is correct

    This command correctly opens inbound TCP port 80 to traffic from any IPv4 address (0.0.0.0/0) and applies the rule only to VM instances tagged with 'web-server', matching the requirement precisely. The combination of --source-ranges 0.0.0.0/0 for internet sources and --target-tags web-server to scope the rule to the intended backend VMs is the standard way to allow HTTP in GCP. No other flags are needed, and the protocol:port syntax 'tcp:80' is accurately specified.

About these practice questions

One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.