Google ACE Firewall rule Practice Question
An engineer wants to allow HTTP traffic from the internet to a set of Compute Engine instances that have the network tag 'web-server'. Which firewall rule should they create?
⚠ Common exam trap
ACE often tests the difference between --source-tags and --source-ranges, and candidates may confuse ingress with egress rules or use the wrong flag for the direction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
gcloud compute firewall-rules create allow-http --allow tcp:80 --source-ranges 0.0.0.0/0 --target-tags web-server
To allow HTTP traffic from the internet to instances with the network tag 'web-server', the firewall rule must specify --allow tcp:80, --source-ranges 0.0.0.0/0 (to allow all internet IPs), and --target-tags web-server (to apply to instances with that tag). This correctly defines an ingress rule allowing TCP port 80 from any source to the tagged instances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
gcloud compute firewall-rules create allow-http --allow tcp:80 --source-tags web-server
Why it's wrong here
--source-tags filters by the source instance's tag, so it permits traffic originating from tagged instances, not traffic arriving at them. It is tempting because tags are involved, but the tag belongs on the destination; --target-tags web-server is the correct axis here.
- ✗
gcloud compute firewall-rules create allow-http --allow tcp:80 --source-tags web-server --target-ranges 0.0.0.0/0
Why it's wrong here
--target-ranges is not a valid gcloud firewall flag; targets are specified with --target-tags or --target-service-accounts, while --source-ranges carries 0.0.0.0/0. It is tempting because it attempts to combine internet sources with tagged targets, but the flag name is wrong.
- ✗
gcloud compute firewall-rules create allow-http --direction egress --allow tcp:80 --destination-ranges 0.0.0.0/0 --target-tags web-server
Why it's wrong here
Setting --direction egress with --destination-ranges 0.0.0.0/0 permits outbound traffic from tagged instances, the reverse of the requirement. It is tempting because --target-tags web-server appears correct, but ingress from the internet needs --direction ingress and --source-ranges 0.0.0.0/0.
- ✓
gcloud compute firewall-rules create allow-http --allow tcp:80 --source-ranges 0.0.0.0/0 --target-tags web-server
Why this is correct
The rule satisfies both constraints: `--source-ranges 0.0.0.0/0` permits internet traffic, and `--target-tags web-server` scopes enforcement to instances carrying that network tag. Google Cloud VPC firewall rules apply to tagged instances, so only the designated Compute Engine instances receive the inbound TCP port 80 allowance.
Go deeper
Related to this question
Learn chapter
Cloud Run and App Engine
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
Key term
Firewall rule
A firewall rule is a set of conditions that tells a firewall which network traffic to allow or block based on attributes like source, destination, port, and protocol.
About these practice questions
One of 775 original ACE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.